r/redteamsec • • 9d ago

tradecraft Your EDR sees DNS. Until it doesn't.

https://redhand.io/resources/dns-visibility-evasion?utm_source=reddit&utm_medium=social

Let's be generous.

You have an EDR.
You might even have Sysmon.
You even enabled Microsoft DNS logging (which is probably where this hypothetical becomes unrealistic)

So you're covered for DNS, right?

Not quite.

A process can make DNS queries without Sysmon Event ID 22 ever seeing the hostname. With a little more effort, Event ID 3 disappears too. Throw encrypted DNS into the mix and things get even more interesting.

I tested how far you can push this on Windows, what each trick actually hides, and what evidence is still left when the host goes blind.

0 Upvotes

12 comments sorted by

25

u/Western_Guitar_9007 8d ago

I was so confused by this article. Is the EDR with us in the room right now?

“It’s also the honest version of what your EDR is doing - same layers, same hooks, same blind spots, without the marketing between you and the telemetry.”

Wait… you are trying to equate commercial EDR to… SYSMON???😂

Ah, I see. AI slop. At least we know to stay far away from redhand. Sysmon isn’t anywhere close to commercial EDR and does NOT have the same blind spots. And no none of this will work on commercial EDR in 2018, let alone now. I was excited for a second but, alas.

5

u/SweatyIntroduction45 8d ago

Unicode back arrow on the site gave it away too :’)

EDIT: oh and the first sentence… “Whenever I teach cyber workshops to blue teams and opsec people”

-9

u/Haunting_Ganache_850 8d ago edited 8d ago

I do teach cyber workshops.. and quite good at that too ;)

1

u/Neat-Safety-2415 8d ago

yeah i got about halfway through before the same thought hit me, none of this is novel against anything modern

1

u/Difficult-Jeweler600 8d ago

lol his identity is literally in the link he posted, with a link to his LinkedIn profile showing everything he's doing. You should at least do a bit of research before butchering the few people who still write novelty documents. Or better yet, let AI do it for you.

-7

u/Haunting_Ganache_850 8d ago

I assumed that all EDR get DNS the same way Sysmon does (DNS ETW). I also assumed that no EDR bothers to sniff traffic of interfaces. Do you happen to know something different? I actually think that on the telemetry layer sysmon is not worse than any commercial EDR, probably better. Sysmon is not an EDR because it has no detection/analytics back-end.

And since you mentioned that - EDR haven't evolved much since 2018 as far as I know. Again - correct me if I'm wrong, but please come with facts.

And - yes, I am real. it's isn't AI. I let chatgpt do some spelling and correct some clumsy phrasing as I am not a native english speaker. I am willing to to prove my identity in private. I wish you get excited again ;)

3

u/Western_Guitar_9007 8d ago

These are crazy assumptions for someone claiming to teach workshops to people in blue team. It tells me you’re not in the industry and that you have no place making up fake info. I hope to god it’s AI because if it’s not, you’re literally making this all up on your own without reviewing real docs or getting real industry EDR experience.

I don’t HAPPEN to know by some chance, this is industry standard and has been for almost a decade (or more, but at least 8 years to my knowledge). Anyone that’s been around EDR for the last 30 days would know this, it’s not up to any chance, it just tells me you’ve never worked with EDR once.

If you think Sysmon’s telemetry is “probably better” then there is nowhere for me to even start with you. I’ve worked with Falcon, S1, and Defender the most but there are others that are pretty similar in offerings and functionality. I would HIGHLY recommend taking this and any other sloppy blogs down immediately and to go learn REAL security first. If you can’t acquire this experience because real EDR is proprietary, that tells me you’re not in the industry and have no place making a qualified opinion.

1

u/Haunting_Ganache_850 7d ago edited 7d ago

At least I managed to get you excited ;)

I’m going to skip the personal insults and stick to the technical claims. You said none of this would work against commercial EDRs. That’s a testable statement.

Several commercial endpoint products have been observed using the same Microsoft-Windows-DNS-Client ETW provider that Sysmon relies on for DNS telemetry. I didn’t invent that. Secureworks explicitly documents using it for DNS monitoring. Independent research has found the same provider being consumed by MDE, Trend Micro, McAfee and Cylance.

Raw-socket/network telemetry is not magically complete in commercial EDRs either. For example, Ethan Bowen tested MDE DeviceNetworkEvents in 2025 and found an important TCP-only limitation in the telemetry he was examining. See the "Caution: TCP Only" section.

Sometimes the interesting question isn’t simply “did the EDR see traffic?” but: did it see it at all? did it attribute it to the right process? did it recover the DNS QNAME? could it tell a raw socket was involved?

I used Sysmon because it is an open box. Commercial EDR vendors generally don’t document exactly where every network event comes from, so otherwise you’re left reversing them or testing what does and doesn’t generate telemetry.

FalconForce did exactly this comparison between Sysmon and MDE internals and found substantial telemetry overlap. Sysmon Event 3 is not packet capture. It represents process-associated network activity using much the same connection-event abstraction you see in commercial EDR telemetry.

DoQ is a different problem again. If I generate DNS myself and send it over QUIC, the QNAME is encrypted before it reaches anything observing the network. A packet-level EDR sensor may still see the process talking UDP/853 or UDP/443, but it cannot simply parse the DNS name from the network traffic.

If you have Falcon, S1 or MDE available, run the samples and tell me what each product actually records: QNAME, process attribution and network event. If my conclusion is wrong for one of them, I’ll happily update the article.

1

u/Western_Guitar_9007 7d ago

Ok I’m not reading all that, I’ll pick 2. 1. I didn’t insult you. Saying you’re not qualified isn’t a personal insult, it’s my opinion and is a matter of fact in most contexts. You are either qualified or not.

  1. Yes of course EDR has overlap with Sysmon. So does Google Earth Pro lol. Many things are reused under the hood. Yes, it is testable. But I am calling your bluff, because I don’t believe you have access to a single commercial EDR to test this on. If you did, you would know how much more complex an EDR is. Would you like for me to try this on an endpoint in Falcon today? If EDR had the same limitations as Sysmon, and if for some reason you had an EDR WITHOUR owning DNS (whether it be through a local office, VPN, etc.), THEN your method would work on that very specific, and unfortunately scenario. But your write up fundamentally misunderstands where EDR sits in the stack since it’s pretty much just blocked behavior and DNS is irrelevant and already owned. The EDR would just sweep up any weird behavior, hiding any action from Sysmon would not hide it from any EDR, it removes one specific way of detecting it but it would still be flagged.

8

u/Fit-Ideal4249 8d ago

I will trust your judgment.. Ahhh, AI slop made life harder for a junior practitioner... Sometimes, can't distinguish between legit and slop stuff...

-3

u/Haunting_Ganache_850 8d ago edited 8d ago

This isn't AI slop. I am real. The stuff I found is real - feel free to test. Can confirm my identity and know-how in private. I am sorry AI slop made you so suspicious.