docs(prd): add PRD 0011 — Catch the exfiltration channel that survives egress filtering - #60
Merged
Merged
Conversation
…s egress filtering DNS is the one protocol almost nobody blocks, which is why it is the durable channel for C2 and data exfiltration. A compromised process encodes data into subdomain labels and reads instructions from the answers, and no outbound TCP connection appears anywhere. That makes it the blind spot in the coverage the other modules give: network-monitor sees a connection to the local resolver and nothing more, log-watcher sees nothing, and egress rules permit it by design. The signatures are distinctive enough to justify a narrow module — long high-entropy labels, TXT-heavy traffic, query rates no human browsing produces, and DGA bursts with high NXDOMAIN rates. Encrypted DNS defeats the whole thing, which is itself worth reporting as posture: the module should say when it is blind. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Specification for the
dns-monitorcore module, listed inPRD.mdand not yet specified.DNS is the one protocol almost nobody blocks, which is why it is the durable channel for C2 and data exfiltration. A compromised process encodes data into subdomain labels and reads instructions from the answers, and no outbound TCP connection appears anywhere.
That makes it the blind spot in the coverage the other modules give: network-monitor sees a connection to the local resolver and nothing more, log-watcher sees nothing, and egress rules permit it by design.
The signatures are distinctive enough to justify a narrow module — long high-entropy labels, TXT-heavy traffic, query rates no human browsing produces, and DGA bursts with high NXDOMAIN rates. Encrypted DNS defeats the whole thing, which is itself worth reporting as posture: the module should say when it is blind.
Spec only — no implementation in this PR.