CISO Security KitThreat HuntingAI CISO

DNS Tunneling Detection

Detect DNS exfiltration and covert channels via entropy, subdomain length, NXDOMAIN ratios, and query rate.

What this skill does

DNS Tunneling Detection is a versioned playbook inside the CISO Security Kit. It runs on the AI CISO agent through the Procux skill runtime, producing structured, auditable output suitable for executive review and regulator submission.

Kit
CISO Security Kit
Category
Threat Hunting
Primary agent(s)
AI CISO
Tags
threat-hunting, dns, exfiltration, tunneling

How to use it

  1. Sign in to your Procux workspace and open the platform dashboard.
  2. Pick the AI CISO agent, then pick DNS Tunneling Detection from the CISO Security Kit catalog.
  3. Provide the required inputs (repo, document, endpoint, jurisdiction) — the agent runs the playbook and returns a structured report.
  4. Review, iterate, or export (PDF / JSON / Markdown) as part of your internal review cycle.

Related skills

← Back to full catalog