# Detecting DNS Exfiltration

**URL:** <https://discuss.elastic.co/t/detecting-dns-exfiltration/285239>\
**Category:** Kibana\
**Created:** [September 27, 2021, 2:21pm UTC](https://discuss.elastic.co/t/detecting-dns-exfiltration/285239 "2021-09-27T14:21:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksremo](https://avatars.discourse-cdn.com/v4/letter/k/5fc32e/32.png) [@ksremo](https://discuss.elastic.co/u/ksremo)\
**Post date:** [September 27, 2021, 2:21pm UTC](https://discuss.elastic.co/t/detecting-dns-exfiltration/285239/1 "2021-09-27T14:21:53Z")

</div>

Hello,  
we ingest dns logs into Elasticsearch.  
the format is  
domain -\> whole domain -\> [deeper.cdn.example.com](http://deeper.cdn.example.com)  
domain1 -\> com  
domain2 -\> example  
domain3 -\> cdn  
domain4 -\> deeper

Now we want to create a siem detection alert if a unusual amount of (sub-)subdomains for a main (sub)domain is resolved.

Example:  
[6346436.evil.c2control.com](http://6346436.evil.c2control.com)  
[3523.evil.c2control.com](http://3523.evil.c2control.com)  
[3524677.evil.c2control.com](http://3524677.evil.c2control.com)  
[352557.evil.c2control.com](http://352557.evil.c2control.com)  
[436246463.evil.c2control.com](http://436246463.evil.c2control.com)

This should work on all level except for the first ([x.com](http://x.com),y,com,and so on).

Any best practice for this usecase?  
thanks

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [September 27, 2021, 2:47pm UTC](https://discuss.elastic.co/t/detecting-dns-exfiltration/285239/2 "2021-09-27T14:47:56Z")

</div>

See [Security anomaly detection configurations | Machine Learning in the Elastic Stack [7.15] | Elastic](https://www.elastic.co/guide/en/machine-learning/current/ootb-ml-jobs-siem.html#security-packetbeat-jobs) for some built in options

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2021, 2:48pm UTC](https://discuss.elastic.co/t/detecting-dns-exfiltration/285239/3 "2021-10-25T14:48:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
