Possible Out-of-Band OAST Callback Domain Resolution via DNS

PremiumReviewedSigma · Medium · v1
Category
dns_query
Author
HuntRule
Published
2026-09-25
Updated
2026-09-25

ATT&CK techniques

Initial Access → C2
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects DNS resolution of well-known out-of-band application security testing and interaction callback domains such as oast.fun, oast.pro, interact.sh, and burpcollaborator.net. These domains are used by exploitation tooling, including scanners for the BeyondTrust CVE-2026-1731 remote code execution flaw, to confirm blind vulnerabilities through out-of-band interaction. Resolution of these domains from server or internal hosts frequently signals active exploitation or reconnaissance against internet-facing services.

Related detections9 linkedT1190 — drag to rearrange
Suspicious Access to Spring Boot Actuator Heapdump Endpoint
Possible FortiWeb Path-Traversal Authentication Bypass Exploitation CVE-2025-64446
Suspicious DNS Query to Interactsh OAST Callback Domains
Possible TrickBot Anchor DNS C2 Registration via HTTP URI (via proxy)
Possible TrickBot DNS Tunneling C2 to westurn.in (via dns_query)
Suspicious Executable Run from IIS aspnet_client or Windows Tasks Directory via process_creation
Suspicious SlowStepper DNS TXT C2 Subdomain Lookup via DNS Query
Suspicious Telerik UI RadAsyncUpload Request Indicating CVE-2019-18935 Exploitation (via webserver)
Malicious IIS Worker Process Spawning Shell for Out-of-Band Interaction via Command Line
Possible Out-of-Band OAST Callback Domain Resolution via DNS
Pivot detection · T1190 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.