Global edit history

What is DNS Tunneling and how to spot exfiltrated data encoded inside subdomains?

Network Exploitation & Wireshark · 2 saved versions

Back to thread

Version 1 (Edit)

Edited by Ishaan Patel · Aug 23, 2026 6:25 PM

0 edit points 0 upvotes
Change note

Content depth regeneration via community:regenerate-content

Title snapshot

What is DNS Tunneling and how to spot exfiltrated data encoded inside subdomains?

Summary snapshot
Detecting high-entropy TXT record queries and long base64 encoded subdomain lookup streams.
Content snapshot
### DNS Exfiltration Signals Monitor for unusually long subdomain query strings (`a8f1x9z.malicious.com`) occurring at rapid volume.
Source snapshot

https://developers.google.com/search/docs

Version 1 (Original Post)

Published by Ishaan Patel · Aug 9, 2026 5:37 AM

Original Publication
Events Log

Post originally created and published to the Global Hub.

Original Title

What is DNS Tunneling and how to spot exfiltrated data encoded inside subdomains?

Original Summary
Detecting high-entropy TXT record queries and long base64 encoded subdomain lookup streams.
Original Content
### DNS Exfiltration Signals Monitor for unusually long subdomain query strings (`a8f1x9z.malicious.com`) occurring at rapid volume.
Original Sources

https://developers.google.com/search/docs