Suspicious DNS Query to Interactsh OAST Callback Domains

PremiumReviewedSigma · Medium · v1
Category
dns_query
Author
HuntRule
Published
2026-09-25
Updated
2026-09-25

ATT&CK techniques

Recon → C2
  1. Resource Dev

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects DNS resolutions for Interactsh out-of-band application security testing domains such as oast.pro, oast.site, oast.me, oast.online, oast.fun and oast.live. These domains receive automated Nuclei and Interactsh scanning callbacks used to confirm blind vulnerabilities, so queries from production hosts indicate the host is being probed or has been compromised in a mass-exploitation campaign.

Related detections9 linkedT1071.004 — drag to rearrange
Suspicious Access to Spring Boot Actuator Heapdump Endpoint
Possible Out-of-Band OAST Callback Domain Resolution via DNS
Possible TrickBot Anchor DNS C2 Registration via HTTP URI (via proxy)
Possible TrickBot DNS Tunneling C2 to westurn.in (via dns_query)
Suspicious SlowStepper DNS TXT C2 Subdomain Lookup via DNS Query
Malicious PIPEDANCE Named Pipe Command and Control Channel via Pipe Created
Suspicious DNS Query for Tor Onion Domain
Possible DNS Tunneling via Excessively Long Query Name
Suspicious Nmap Scanner Probe URIs in HTTP Requests (via webserver)
Suspicious DNS Query to Interactsh OAST Callback Domains
Pivot detection · T1071.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.