Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is command and control over DNS?

DNS command and control encodes identifiers, tasks or data in domain-name queries and responses. Unusual-looking DNS is not enough: legitimate security, tracking and cloud services can produce long, frequent or unique names.

Compare pattern, process and response

Preserve complete queries and answers, timestamps, source device and process, resolver, registration context and related endpoint activity. Keep original label order and content before normalisation because encoding may depend on it.

Compare length, frequency, uniqueness and response changes with the normal pattern for that process and device. Endpoint observations show query generation, while resolver logs show what was forwarded; explain gaps caused by caching or filtering.

Prove exchange and effect

A query may be an attempted check-in with no meaningful answer. Decoded content, changing responses and resulting commands or files can support an actual channel. Low-volume activity may still be control traffic, so one threshold is not decisive.

Specialist analysis may be needed, but preserve the raw evidence first and state when interpretation remains inferential.

Key takeaway

Establish DNS control from the responsible process, sustained query-response pattern and resulting behaviour - not from one encoded-looking name.

Reference: CIM-151Cyber Incidents & Offender Methods