Glossary
DNS infiltration and exfiltration
DNS infiltration and exfiltration are techniques that abuse the domain name system (DNS) to establish covert communication channels between compromised systems and attacker-controlled infrastructure. By embedding commands or data within DNS traffic, attackers can bypass traditional security controls and move information into or out of an organization’s network while appearing to generate legitimate DNS activity.
Because DNS is a foundational internet service that is often trusted and allowed through security controls, it can become an attractive channel for attackers seeking to evade detection.
{{anchor:Overview}}
How DNS infiltration and exfiltration work
Attackers commonly use a technique known as DNS tunneling, which encapsulates commands, payloads, or sensitive data within DNS queries and responses.
A typical attack may involve:
- Compromising an endpoint through malware or phishing
- Establishing communication with attacker-controlled DNS infrastructure
- Embedding commands within DNS responses
- Encoding sensitive information within DNS queries
- Using DNS traffic to maintain command-and-control (C2) communications
- Bypassing traditional network monitoring tools and firewalls
Because DNS traffic is often viewed as routine network activity, malicious communications can remain undetected for extended periods.
{{anchor:Why they matter}}
Why DNS infiltration and exfiltration matter
DNS-based communications are frequently used in advanced cyberattacks, espionage campaigns, and long-term network compromises.
Successful DNS infiltration and exfiltration can result in:
- Theft of sensitive or proprietary information
- Data breaches and regulatory exposure
- Persistent attacker access to internal systems
- Intellectual property loss
- Operational disruption
- Financial and reputational damage
The ability to use DNS as a covert communications channel makes these attacks particularly difficult to identify without specialized monitoring and analysis.
{{anchor:Examples}}
Reducing DNS infiltration and exfiltration risk
Organizations can strengthen defenses against DNS-based threats by implementing a layered security strategy that includes:
- Protective DNS controls
- DNS traffic monitoring and analysis
- Restricting unauthorized outbound DNS communications
- Endpoint protection and anti-malware solutions
- Threat intelligence integration
- Regular network and security audits
- DNS logging and anomaly detection
Proactive visibility into DNS activity is critical for identifying suspicious behavior before it leads to data loss or broader compromise.
{{anchor:How DigiCert helps}}
How DigiCert can help
DigiCert UltraDDR helps organizations detect and block malicious DNS activity that may indicate infiltration, exfiltration, or command-and-control communications. As a protective DNS solution, UltraDDR uses continuously updated threat intelligence and advanced DNS analysis to identify suspicious domains, adversary infrastructure, and malicious communications before they can impact the organization.