Analyzing Dns Logs For Exfiltration

mukul975/Anthropic-Cybersecurity-Skills/skills/analyzing-dns-logs-for-exfiltration

by mukul97554a798831d2266a3ca61ce68a7acb80b81160d57Apache-2.034K starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 5 weeks ago

Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls.

Includes scriptsSecurity
  1. 54a798831d2266a3ca61ce68a7acb80b81160d57Currentcommit 54a7988Published Oct 9, 2026

Source and attribution

Source:mukul975/Anthropic-Cybersecurity-Skillsinskills/analyzing-dns-logs-for-exfiltrationat commit54a7988

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal