A technique that embeds other data within DNS traffic to abuse it as a communication channel.
A technique that embeds arbitrary data in DNS query and response fields, abusing them as a communication channel, such as for data exfiltration. Because many firewalls allow DNS traffic (port 53) through unconditionally, this technique often still gets through even when every other channel is blocked -- detection typically relies on spotting statistical anomalies in query frequency or domain names.
© 2026 ITBGM