- Hands-On Network Forensics
- Nipun Jaswal
- 112字
- 2021-06-24 16:04:17
DNS servers logs
Name server query logs can help understand IP-to-hostname resolution at specific times. Consider a scenario where, as soon as a system got infected with malware on the network, it tried to connect back to a certain domain for command and control. Let's see an example as follows:

We can see in the preceding screenshot that a DNS request was resolved for malwaresamples.com website and the resolved IP address was returned.
Having access to the DNS query packets can reveal Indicators of Compromise for a particular malware on the network while quickly revealing the IP address of the system making the query, and can be dealt with ease.
推薦閱讀
- Web漏洞分析與防范實戰:卷1
- CSO進階之路:從安全工程師到首席安全官
- Mastering Kali Linux for Advanced Penetration Testing
- 硬黑客:智能硬件生死之戰
- Spring Security(Third Edition)
- Learning Devise for Rails
- 局域網交換機安全
- 數據安全與流通:技術、架構與實踐
- 從實踐中學習密碼安全與防護
- 空間群組密鑰管理研究:基于自主的深空DTN密鑰管理
- 持續集成:軟件質量改進和風險降低之道
- 數據安全架構設計與實戰
- 捍衛隱私
- Mastering Python for Networking and Security
- 物聯網信息安全技術