BIOC Informational

Scripting engine makes connections over DNS ports

Scripting engine makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection.

Module:
Platform Analytics
Agent event type:
Network
Category:
Exfiltration
Status:
Enabled
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
Indicator:

Network action type = failed , outgoing AND remote port = 53 Process os parent name = cmd.exe , powershell.exe , wscript.exe , cscript.exe , mshta.exe AND os parent signature = Signed Host host os != linux AND host os = windows

Preventable: yes