Open cardosec

Case F460C7 · Network · L3 Applied

Long TXT Queries from Finance

Practise as: Incident drill · Interview

Live alertSince 01:00, FIN-LT-042 has sent 60,000 TXT queries for random 50-character subdomains of cdn-metrics-sync.com, a domain registered five days ago.

Interview questionWhat does this look like to you, and how do you respond?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. High-entropy, high-volume TXT queries to a newly registered domain strongly indicate DNS tunneling C2 or exfil
  2. Contain: isolate FIN-LT-042 and sinkhole or block the domain at internal resolvers and protective DNS
  3. Estimate data volume from query sizes; decode sample labels if encoding is simple (base32/hex)
  4. Endpoint triage: find the process issuing queries (Sysmon Event 22), persistence, and initial access vector
  5. Hunt other hosts querying the domain or similar patterns; check whether finance data was accessed

If the interviewer pushes back

  • The resolver logs only show your DNS server as the client. How do you find the real source host?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.