mirror of
https://github.com/SHOGGOTH-SECTOR/sica-fondt.git
synced 2026-08-01 08:30:20 +00:00
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):
- brain/ LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
dispatch, A51 channels, and the OSINT cluster
- knowledge/ LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
MITRE ATT&CK data
- reference/ defensive threat-reference (C3, shhbruh doc) + AdaYaml parser
License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.
Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.
https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
47 lines
2.2 KiB
Markdown
47 lines
2.2 KiB
Markdown
# Standards and References - DNS Tunneling Detection
|
|
|
|
## MITRE ATT&CK References
|
|
|
|
| Technique | Name | Description |
|
|
|-----------|------|-------------|
|
|
| T1071.004 | Application Layer Protocol: DNS | DNS-based C2 communication |
|
|
| T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol | Data theft via DNS |
|
|
| T1572 | Protocol Tunneling | IP-over-DNS tunneling |
|
|
| T1568.002 | Domain Generation Algorithms | Algorithmically generated domains |
|
|
| T1132.001 | Data Encoding: Standard Encoding | Base32/64 in DNS queries |
|
|
|
|
## DNS Tunneling Detection Thresholds
|
|
|
|
| Indicator | Threshold | Rationale |
|
|
|-----------|-----------|-----------|
|
|
| Query length | > 50 characters | Normal queries average 20-30 chars |
|
|
| Subdomain label length | > 30 characters | Max label is 63; tunneling uses near-max |
|
|
| Subdomain entropy | > 3.5 bits/char | Base32/64 encoding produces high entropy |
|
|
| Unique subdomains per domain | > 100/hour | Legitimate domains have few unique subs |
|
|
| Query volume to single domain | > 100/hour | Sustained high volume indicates tunneling |
|
|
| TXT record query ratio | > 50% to domain | TXT queries carry more data |
|
|
| NULL record queries | Any volume | Rarely used legitimately |
|
|
|
|
## DNS Tunneling Tools
|
|
|
|
| Tool | Protocol | Record Types | Data Rate | Detection Difficulty |
|
|
|------|----------|-------------|-----------|---------------------|
|
|
| iodine | IP-over-DNS | NULL, TXT, CNAME, A | ~100 Kbps | Medium |
|
|
| dnscat2 | C2 over DNS | TXT, CNAME, MX | ~10 Kbps | Medium |
|
|
| DNSExfiltrator | Exfil over DNS | TXT, A | ~5 Kbps | Medium-Hard |
|
|
| Cobalt Strike DNS | C2 | A, TXT | Variable | Hard |
|
|
| dns2tcp | TCP-over-DNS | TXT, KEY | ~50 Kbps | Medium |
|
|
| Heyoka | DNS exfiltration | All types | Variable | Hard |
|
|
|
|
## Zeek Log Fields for DNS Analysis
|
|
|
|
| Field | Description | Tunnel Relevance |
|
|
|-------|-------------|-----------------|
|
|
| query | Full DNS query name | Length and entropy analysis |
|
|
| qtype_name | Query record type | TXT/NULL/CNAME anomalies |
|
|
| answers | Response content | Response size analysis |
|
|
| rcode_name | Response code | NXDOMAIN patterns |
|
|
| id.orig_h | Source IP | Source identification |
|
|
| AA | Authoritative answer | Non-authoritative responses |
|
|
| rejected | Query rejected | Filtering effectiveness |
|