Post #4028515
2026-07-23 05:20 UTC
@k3ym0@infosec.exchange
The first time I came across DNS tunneling in the wild was traffic monitoring hardware sold as a security device.. Turns out it was trying to do DNS tunneling to check for a valid licence.. My advice was to dump it was not taken.
Theres always one weirdo somewhere tailing their DNS logs!
Replies (1)
-
@djb@social.shirow.net 2026-07-23 05:52
@vk3kri@mastodon.radio @k3ym0@infosec.exchange anomaly detection on DNS logs FTW https://www.sans.org/white-papers/34152