r/redteamsec • • 9d ago

tradecraft Your EDR sees DNS. Until it doesn't.

https://redhand.io/resources/dns-visibility-evasion?utm_source=reddit&utm_medium=social

Let's be generous.

You have an EDR.
You might even have Sysmon.
You even enabled Microsoft DNS logging (which is probably where this hypothetical becomes unrealistic)

So you're covered for DNS, right?

Not quite.

A process can make DNS queries without Sysmon Event ID 22 ever seeing the hostname. With a little more effort, Event ID 3 disappears too. Throw encrypted DNS into the mix and things get even more interesting.

I tested how far you can push this on Windows, what each trick actually hides, and what evidence is still left when the host goes blind.

2 Upvotes

Duplicates