incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
CybersecurityhardDNS Tunneling ExfiltrationCritical asset
Scenario

Workstation issuing ~5,000 long-subdomain DNS queries / hour to one 4-day-old TLD — no matching TCP/UDP outbound, design CAD files accessed

A hard Cybersecurity scenario on DNS Tunneling Exfiltration.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.

catalog id · dns-tunnel-exfil-design-engineer

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • DNS-tunnel pattern recognition
  • Anomaly-driven outbound scoping
MITRE ATT&CKmitre-attack
  • Application Layer Protocol · Command and ControlT1071 · TA0011
    MappedHigh confidence

    Trains DNS-channel triage for suspected exfiltration.

  • Exfiltration Over Alternative Protocol · ExfiltrationT1048 · TA0010
    MappedMedium confidence

    Trains scoping of non-standard exfil channels.

MITRE D3FENDmitre-d3fend
  • Network Traffic AnalysisD3-NTA
    MappedHigh confidence

    Trains the DNS-traffic visibility posture the scenario centers on.

  • Network Traffic FilteringD3-NTF
    MappedMedium confidence

    Trains the outbound-filtering control once the domain is scoped.

NIST CSF 2.0nist-csf-2
  • Anomalies and Events · DetectDE.AE · DE
    MappedHigh confidence

    Trains anomaly-detection reasoning on DNS telemetry.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains DNS-pattern triage and scoping.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains DNS-based containment workflow.

CISA Cybersecurity Performance Goalscisa-cpg
  • Detecting Relevant Threats and TTPs3.A
    MappedHigh confidence

    Trains the detection-engineering baseline the scenario exercises.

CIS Controls v8cis-controls
  • Network Monitoring and DefenseControl 13
    MappedHigh confidence

    Trains the network-monitoring control the scenario exercises.

  • Audit Log ManagementControl 8
    MappedMedium confidence

    Trains the DNS-log review the response depends on.