tunnel_record_anomaly
Detect DNS tunneling by analyzing query patterns for NULL, TXT, CNAME, and MX record abuse, revealing data exfiltration attempts.
Instructions
Analyzes DNS queries for record type abuse patterns commonly used in tunneling. Detects indicators of NULL, TXT, CNAME, and MX record abuse, plus anomalous query patterns consistent with data exfiltration.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| queries | Yes | List of DNS query names (FQDNs) to analyze for record type anomaly patterns |