Generic.DNS.Tunnel.Detection.Variant.A

description-logoDescription

This indicates detection of suspicious traffics that might be from a DNS Tunnel.
DNS tunnels are proxy tools that can tunnel data over DNS to bypass firewall policy. Some malware and APT attacks have used DNS tunnels to communicate with C&C servers.

affected-products-logoAffected Products

All systems

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Monitor traffics from the network for any suspicious activity.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-12-19 15.748 Default_action:pass:drop
2019-11-29 15.736 Sig Added
2019-11-26 15.731