acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert
$ npx -y skills add Mikaru0Mystic/sectinel --skill analyzing-dns-logs-for-exfiltration --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-dns-logs-for-exfiltrationContext preview
The summary Claude sees to decide when to auto-load this skill.
Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert
name: analyzing-dns-logs-for-exfiltration description: 'Analyzes DNS query logs to detect data exfiltration via DNS tunneling, DGA domain communication, and covert C2 channels using entropy analysis, query volume anomalies, and subdomain length detection in SIEM platforms. Use when SOC teams need to identify DNS-based threats that bypass traditional network security controls. ' domain: cybersecurity subdomain: soc-operations tags: - soc - dns - exfiltration - dns-tunneling - dga - c2-detection - splunk - threat-detection version: '1.0' author: mahipal license: Apache-2.0 atlas_techniques: - AML.T0024 - AML.T0056 - AML.T0086 nist_csf: - DE.CM-01 - DE.AE-02 - RS.MA-01 - DE.AE-06
Use this skill when:
**Do not use** for standard DNS troubleshooting or availability monitoring — this skill focuses on security-relevant DNS abuse detection.
DNS tunneling encodes data in subdomain labels, creating unusually long queries:
index=dns sourcetype="stream:dns" query_type IN ("A", "AAAA", "TXT", "CNAME", "MX")
| eval domain_parts = split(query, ".")
| eval subdomain = mvindex(domain_parts, 0, mvcount(domain_parts)-3)
| eval subdomain_str = mvjoin(subdomain, ".")
| eval subdomain_len = len(subdomain_str)
| eval tld = mvindex(domain_parts, -1)
| eval registered_domain = mvindex(domain_parts, -2).".".tld
| where subdomain_len > 50
| stats count AS queries, dc(query) AS unique_queries,
avg(subdomain_len) AS avg_subdomain_len,
max(subdomain_len) AS max_subdomain_len,
values(src_ip) AS sources
by registered_domain
| where queries > 20
| sort - avg_subdomain_len
| table registered_domain, queries, unique_queries, avg_subdomain_len, max_subdomain_len, sourcesDomain Generation Algorithms produce random-looking domains:
index=dns sourcetype="stream:dns" | eval domain_parts = split(query, ".") | eval sld = mvindex(domain_parts, -2) | eval sld_len = len(sld) | eval char_count = sld_len | eval vowels = len(replace(sld, "[^aeiou]", "")) | eval consonants = len(replace(sld, "[^bcdfghjklmnpqrstvwxyz]", "")) | eval digits = len(replace(sld, "[^0-9]", "")) | eval vowel_ratio = if(char_count > 0, vowels / char_count, 0) | eval digit_ratio = if(char_count > 0, digits / char_count, 0) | where sld_len > 12 AND (vowel_ratio < 0.2 OR digit_ratio > 0.3) | stats count AS queries, dc(query) AS unique_domains, values(src_ip) AS sources by query | where unique_domains > 10 | sort - queries
**Python-based Shannon Entropy Calculation for DNS queries:**
import math
from collections import Counter
def shannon_entropy(text):
"""Calculate Shannon entropy of a string"""
if not text:
return 0
counter = Counter(text.lower())
length = len(text)
entropy = -sum(
(count / length) * math.log2(count / length)
for count in counter.values()
)
return round(entropy, 4)
# Test with examples
normal_domain = "google" # Low entropy
dga_domain = "x8kj2m9p4qw7n" # High entropy
tunnel_subdomain = "aGVsbG8gd29ybGQ.evil.com" # Base64 encoded data
print(f"Normal: {shannon_entropy(normal_domain)}") # ~2.25
print(f"DGA: {shannon_entropy(dga_domain)}") # ~3.70
print(f"Tunnel: {shannon_entropy(tunnel_subdomain)}") # ~3.50
# Threshold: entropy > 3.5 for subdomain = likely tunneling/DGA**Splunk implementation of entropy scoring:**
index=dns sourcetype="stream:dns" | eval domain_parts = split(query, ".") | eval check_string = mvindex(domain_parts, 0) | eval check_len = len(check_string) | where check_len > 8 | eval chars = split(check_string, "") | stats count AS total_chars, dc(chars) AS unique_chars by query, src_ip, check_string, check_len | eval entropy_estimate = log(unique_chars, 2) * (unique_chars / check_len) | where entropy_estimate > 3.5 | stats count AS high_entropy_queries, dc(query) AS unique_queries by src_ip | where high_entropy_queries > 50 | sort - high_entropy_queries
Identify hosts generating abnormal DNS traffic:
index=dns sourcetype="stream:dns" earliest=-24h | bin _time span=1h | stats count AS queries, dc(query) AS unique_domains by src_ip, _time | eventstats avg(queries) AS avg_queries, stdev(queries) AS stdev_queries by src_ip | eval z_score = (queries - avg_queries) / stdev_queries | where z_score > 3 OR queries > 5000 | sort - z_score | table _time, src_ip, queries, unique_domains, avg_queries, z_score
**Detect TXT record abuse (common tunneling method):**
index=dns sourcetype="stream:dns" query_type="TXT"
| stats count AS txt_queries, dc(query) AS unique_txt_domains,
values(query) AS domains by src_ip
| where txt_queries > 100
| eval suspicion = case(
txt_queries > 1000, "CRITICAL — Likely DNS tunneling",
txt_queries > 500, "HIGH — Possible DNS tunneling",
txt_queries > 100, "MEDIUM — Unusual TXT volume"
)
| sort - txt_queries
| table src_ip, txt_queries, unique_txt_domains, suspicionOpen-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative