CompTIA PenTest+ (PT0-003)Post-exploitation and Lateral MovementHard

A penetration tester has compromised a Windows domain controller and wants to exfiltrate sensitive files, but direct outbound connections are heavily monitored. The tester notices that the domain controller can resolve external DNS queries. To avoid detection, the tester decides to use DNS exfiltration. Which of the following tools or techniques is best suited for encoding and sending data via DNS queries?

  1. ANetcat for raw TCP/UDP transfer.
  2. BBurp Suite's Collaborator for out-of-band data.
  3. CPowerShell with a custom script to encode data into subdomain names.
  4. DNmap for port scanning through a DNS proxy.
Show answer & explanation

Correct answer: C. PowerShell with a custom script to encode data into subdomain names.

While tools like `iodine` or `dnscat2` are purpose-built for DNS tunneling, a custom PowerShell script offers maximum flexibility and stealth. It can encode arbitrary data into subdomain names and send them as DNS queries to a controlled external DNS server, making it particularly effective for exfiltrating sensitive data when direct network connections are monitored. This avoids deploying new binaries and can be customized to mimic legitimate DNS traffic.

Why the other options are wrong

  • A. Netcat requires direct TCP/UDP connections, which are heavily monitored.
  • B. Burp Suite's Collaborator is primarily for OOB detection, not large-scale data exfiltration via DNS.
  • D. Nmap is for network scanning, not for exfiltrating data via DNS.

Custom DNS Exfiltration Script

Developing a custom script (e.g., in PowerShell, Python) to encode sensitive data into subdomain names and send them as DNS queries to a controlled external DNS server for exfiltration.

  • Offers high degree of customization and stealth compared to off-the-shelf tools.
  • Requires a controlled external DNS server to receive and decode queries.
  • Can bypass network monitoring that focuses on common C2 traffic patterns.

Memory trick: Custom DNS queries hide data in plain sight.

More Post-exploitation and Lateral Movement questions