White Paper
TAXONOMY OF SolarWinds SUNBURST DNS Abuse Tactics
The SUNBURST attack used enterprise DNS weaknesses to hide its command‑and‑control traffic, making detection extremely difficult. Because DNS generates massive volumes of noisy queries, malicious activity can blend in unnoticed. SUNBURST relied on a rare domain generation algorithm to exfiltrate data and communicate with attackers, bypassing traditional logging and security controls. This tactic revealed how easily DNS can be abused through hijacking, cache poisoning, and covert channels, raising concerns about how organizations can detect similar threats in the future and highlighting the need for deeper DNS visibility and analysis.
