TACTIC: COMMAND AND CONTROL

DNS Tunneling (T1071.004): real cases

MITRE Definition ↗
Adversaries encode commands and data within DNS query and response packets.

Key Facts

Technique ID
T1071.004
Command and Control
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1071.004.
  • Tactical Phase: Command and Control.
  • Substantiated in 1 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Indictment ¶ 35, Page 16
"X-Agent malware used DNS tunneling over port 53 to transmit command output across restricted network perimeter firewalls."
U.S. District Court for the District of Columbia View full case dossier →