Suspicious DNS Query To Interactsh OAST Domain

PremiumReviewedSigma · High · v1
Category
dns_query
Author
HuntRule
Published
2026-10-02
Updated
2026-10-02

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects DNS lookups to *.oast.fun, an out-of-band application security testing domain used by the actors exploiting CVE-2026-1731 to confirm blind command injection. A callback to an OAST domain from a server indicates the host executed attacker-controlled code during exploitation. Production systems have no legitimate reason to resolve these interaction domains.

Related detections9 linkedT1190 — drag to rearrange
Suspicious Cisco IOS XE Privileged Account Creation via CVE-2023-20198
Suspicious SmarterMail Force Password Reset API Request Indicating Account Takeover
Possible CrushFTP CVE-2025-31161 Authentication Bypass via Webserver
Suspicious SolarWinds Web Help Desk Java Process Spawning Command Shell
Malicious IIS Worker Process Spawning PowerShell via Gladinet CentreStack Exploit
Suspicious PowerShell Out-of-Band Request to Interactsh Domain
Exchange Worker Process Spawning Command Shell via OWASSRF
Suspicious PowerShell Spawned by SysAid Java Process
Suspicious Shell or Installer Spawned by ActiveMQ Java Process
Suspicious DNS Query To Interactsh OAST Domain
Pivot detection · T1190 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.