Open chrisforce1 opened 4 years ago
As per https://github.com/krmaxwell/dns-exfiltration we should synthesize Base64 encoding and exfiltration of data to hostnames under base64.alphasoc.xyz, as below:
base64.alphasoc.xyz
/dev/random
AAAAAAAAAAAxMjM0NTY3OA==.base64.alphasoc.xyz
Module description for the table in the documentation as below.
base64-dns
We should probably rename sandbox.alphasoc.xyz to tunnel.alphasoc.xyz too. Thoughts?
sandbox.alphasoc.xyz
tunnel.alphasoc.xyz
This is a lower priority as it is blocked by https://github.com/alphasoc/riswiz/issues/321.
As per https://github.com/krmaxwell/dns-exfiltration we should synthesize Base64 encoding and exfiltration of data to hostnames under
base64.alphasoc.xyz
, as below:/dev/random
or similarAAAAAAAAAAAxMjM0NTY3OA==.base64.alphasoc.xyz
)Module description for the table in the documentation as below.
base64-dns
We should probably rename
sandbox.alphasoc.xyz
totunnel.alphasoc.xyz
too. Thoughts?