Splunk has removed or deprecated several DNS-focused detections and investigations from its Threat Research content library, including analytics for DNS tunnels, DNS data exfiltration, suspicious TXT records, long TXT responses, clients querying multiple DNS servers, dynamic DNS provider traffic, and investigations for DNS traffic ratios and the process responsible for DNS traffic. Splunk said some content no longer effectively detected the intended activity, overlapped with newer analytics, depended on unsupported Enterprise Security investigation features, or broke because of compatibility issues with Splunk AI Toolkit 5.7.0 and related data science components; in some cases, Splunk pointed users to replacement rules such as DNS query length outlier detections or updated dynamic-DNS analytics.
The removals affect detections tied to well-known attacker tradecraft in which adversaries use DNS for command-and-control and exfiltration, including DNS tunneling, abuse of TXT, A, and AAAA records, and infrastructure-hiding techniques such as dynamic DNS and domain generation algorithms (DGAs). MITRE ATT&CK documents these behaviors under techniques including T1071.004 for DNS-based application-layer C2 and T1568.002 for DGAs, while prior threat research has shown malware and intrusion sets using DNS because it is widely allowed through firewalls and can conceal beaconing, payload delivery, and data theft inside normal-looking name-resolution traffic.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research updated and published removal notices for multiple deprecated DNS-related detections and investigations in its content library, documenting their unsupported status and replacement guidance where applicable.
Palo Alto Networks Unit 42 published a report describing how attackers abuse DNS for command-and-control, data exfiltration, and payload delivery, and outlined defensive recommendations and common tunneling tools.
MITRE ATT&CK published the Enterprise sub-technique entry for Domain Generation Algorithms (T1568.002), cataloging malware and threat groups that use DGAs for command-and-control communications.
Splunk Threat Research removed the detections Detect suspicious DNS TXT records using pretrained model in DSDL and Detect DNS Data Exfiltration using pretrained model in DSDL in content library version 5.26.0. Splunk said both were no longer maintained because they did not work with Splunk AI Toolkit 5.7.0 and Python for Scientific Computing for Linux 64-bit 4.3.0.
Splunk Threat Research removed several DNS-related detections and investigations in content version 5.2.0, including Clients Connecting to Multiple DNS Servers, Detection of DNS Tunnels, Detect Long DNS TXT Record Response, Detect web traffic to dynamic domain providers, Get DNS traffic ratio, and Get Process Responsible For The DNS Traffic. Reasons included ineffective detection logic, duplicate coverage, replacement by other content, log-source changes, and deprecation of Investigations in Splunk Enterprise Security 8.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceunit42.paloaltonetworks.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.