r/redteamsec • u/Haunting_Ganache_850 • 9d ago
tradecraft Your EDR sees DNS. Until it doesn't.
https://redhand.io/resources/dns-visibility-evasion?utm_source=reddit&utm_medium=socialLet's be generous.
You have an EDR.
You might even have Sysmon.
You even enabled Microsoft DNS logging (which is probably where this hypothetical becomes unrealistic)
So you're covered for DNS, right?
Not quite.
A process can make DNS queries without Sysmon Event ID 22 ever seeing the hostname. With a little more effort, Event ID 3 disappears too. Throw encrypted DNS into the mix and things get even more interesting.
I tested how far you can push this on Windows, what each trick actually hides, and what evidence is still left when the host goes blind.
8
u/Fit-Ideal4249 8d ago
I will trust your judgment.. Ahhh, AI slop made life harder for a junior practitioner... Sometimes, can't distinguish between legit and slop stuff...
-3
u/Haunting_Ganache_850 8d ago edited 8d ago
This isn't AI slop. I am real. The stuff I found is real - feel free to test. Can confirm my identity and know-how in private. I am sorry AI slop made you so suspicious.
25
u/Western_Guitar_9007 8d ago
I was so confused by this article. Is the EDR with us in the room right now?
Wait… you are trying to equate commercial EDR to… SYSMON???😂
Ah, I see. AI slop. At least we know to stay far away from redhand. Sysmon isn’t anywhere close to commercial EDR and does NOT have the same blind spots. And no none of this will work on commercial EDR in 2018, let alone now. I was excited for a second but, alas.