{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/dns-anomaly/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["low"],"_cs_tags":["command-and-control","exfiltration","initial-access","machine-learning","network-traffic","dns-anomaly","elastic-security","endpoint-detection"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis brief details the \u0026quot;Unusual DNS Activity\u0026quot; detection rule, powered by Elastic's machine learning capabilities, designed to identify atypical DNS queries that deviate significantly from a system's baseline behavior. Unidentified adversaries leverage rare or newly registered domains for various stages of an attack lifecycle, including initial access (e.g., distributing malware via phishing links), establishing persistent presence, maintaining command-and-control channels, or exfiltrating data. The rule analyzes network traffic and endpoint data collected by Elastic Defend or Network Packet Capture integrations to spot these anomalies. While not tied to a specific campaign or threat actor, this detection is critical for identifying covert communications that might bypass traditional signature-based security controls, signaling the presence of advanced malware or targeted attacks. This proactive detection helps defenders identify and mitigate potential compromises early in the attack chain.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Access\u003c/strong\u003e: Adversaries initiate an attack through vectors such as phishing emails containing malicious links or attachments, or by exploiting software vulnerabilities.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eExecution\u003c/strong\u003e: A victim interacts with the malicious content (e.g., clicking a link, opening a document), leading to the execution of attacker-controlled code or malware on the system.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCallback/Payload Request\u003c/strong\u003e: The executed malicious code attempts to connect to attacker infrastructure to download additional payloads or establish an initial command-and-control (C2) channel.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRare DNS Query\u003c/strong\u003e: This communication involves making a DNS query to an uncommon, newly registered, or otherwise obscure domain specifically controlled by the attacker, which deviates from the system's normal DNS traffic patterns.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCommand and Control (C2)\u003c/strong\u003e: If successful, the malware periodically communicates with the attacker's infrastructure using these rare DNS domains for ongoing C2 instructions, updates, or tasking.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eData Exfiltration\u003c/strong\u003e: In later stages, sensitive data may be encoded and transmitted out of the compromised network to attacker-controlled domains, potentially via DNS tunneling or other protocols using unusual DNS requests.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful attacks involving unusual DNS activity can lead to a range of severe consequences. If the rare DNS query is part of an initial access attempt, it can lead to full system compromise, data theft, or ransomware deployment across the organization. For established C2 or data exfiltration, the impact includes sustained adversary presence within the network, intellectual property loss, financial damage, and reputational harm due to undetected breaches. The nature of these attacks, relying on statistically rare events, means they often indicate sophisticated adversaries bypassing standard defenses.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the \u0026quot;Unusual DNS Activity\u0026quot; machine learning job (ID: \u003ccode\u003erare_dns_question_ea\u003c/code\u003e) in your Elastic Security environment to enable this anomaly detection rule.\u003c/li\u003e\n\u003cli\u003eEnsure that data from Elastic Defend and Network Packet Capture integrations is properly configured and flowing into your Elastic Security app to provide the necessary log sources for the ML rule.\u003c/li\u003e\n\u003cli\u003eWhen an alert triggers, review the DNS query logs to identify the specific rare domain that caused the alert and determine its reputation using available threat intelligence sources.\u003c/li\u003e\n\u003cli\u003eAnalyze the source IP address associated with the unusual DNS query to identify the affected device or user, and examine its network activity for any other anomalies.\u003c/li\u003e\n\u003cli\u003eImplement whitelisting for legitimate internal applications or cloud services that are known to generate rare DNS queries to reduce false positives.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T18:27:59Z","date_published":"2026-07-28T18:27:59Z","id":"https://feed.craftedsignal.io/briefs/2026-07-unusual-dns-activity/","summary":"An Elastic machine learning rule detects rare and unusual DNS queries that indicate potential malicious network activity, including initial access via phishing or malicious documents, persistence, command-and-control (C2) communication, or data exfiltration attempts by adversaries.","title":"Unusual DNS Activity Detected by Machine Learning","url":"https://feed.craftedsignal.io/briefs/2026-07-unusual-dns-activity/"}],"language":"en","title":"CraftedSignal Threat Feed - Dns-Anomaly","version":"https://jsonfeed.org/version/1.1"}