DNS Exfiltration via DNSExfiltrator

Rule Info

Name
DNS Exfiltration via DNSExfiltrator
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects DNS exfiltration activity using the DNSExfiltrator tool, which encodes data in DNS queries using certain encoding.
Date
2026-04-02 00:00:00
Modified
None
Id
682b3c01-72cf-4131-ac4f-4256ab7f73c5
Tags
attack.exfiltration attack.t1048.003 attack.command-and-control attack.t1071.004
Type
Nextron Sigma feed only (private)

Rule History