What is exfiltration over DNS?¶
DNS exfiltration encodes data into domain-name queries or responses so it can leave through name-resolution traffic. Long or unusual queries are not proof: legitimate tracking, cloud and security services can look similar.
Reconstruct the resolver path¶
Preserve complete queries and answers, sequence, timestamps, source device and process, resolver, destination domain and endpoint activity. If content appears encoded, retain original labels and ordering before normalisation.
A query generated locally may be cached, filtered or blocked before reaching an authoritative server. Compare endpoint and resolver logs to determine how far it travelled and state where evidence ends.
Test content and capacity¶
Specialist decoding can link query labels to source data, but missing queries may make recovery partial. Compare the recoverable content and estimated channel capacity with the claimed dataset and available period.
A few short queries cannot support an implausibly large transfer. Even a complete outbound sequence does not prove the receiver decoded or retained it, so successful transmission and recipient use remain separate findings.
Key takeaway
Prove DNS exfiltration through the responsible process, ordered encoded content and resolver path, with a technically plausible data volume and explicit receipt limits.