← LibraryTechnique entry
DNS-TUNNEL-EXFILExfiltration
DNS Tunneling Exfil (iodine / dnscat2)
Encode exfil data into subdomain queries — works wherever recursive DNS is allowed out, often the last egress channel open.
§ Where this technique fits
DNS-TUNNEL-EXFIL is catalogued under the Exfiltration tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 3 on average.
§ Dossiers chaining this technique
§ What commonly comes next
- 01DNS-over-HTTPS C2 Channelseen 1×DNS-DOH-C2 · Command and Control