官术网_书友最值得收藏!

DNS servers logs

Name server query logs can help understand IP-to-hostname resolution at specific times. Consider a scenario where, as soon as a system got infected with malware on the network, it tried to connect back to a certain domain for command and control. Let's see an example as follows:

We can see in the preceding screenshot that a DNS request was resolved for malwaresamples.com website and the resolved IP address was returned.

Having access to the DNS query packets can reveal Indicators of Compromise for a particular malware on the network while quickly revealing the IP address of the system making the query, and can be dealt with ease.

主站蜘蛛池模板: 吴桥县| 栖霞市| 盖州市| 沅江市| 普兰县| 麻栗坡县| 米泉市| 河源市| 合江县| 天门市| 萝北县| 贵港市| 余姚市| 山西省| 龙里县| 林芝县| 兴文县| 德庆县| 吉林市| 乌拉特中旗| 大竹县| 弋阳县| 石河子市| 金沙县| 武胜县| 长丰县| 邢台县| 谢通门县| 达州市| 通道| 弥渡县| 琼海市| 泗水县| 祁阳县| 丹棱县| 西乡县| 延安市| 晋宁县| 平遥县| 山西省| 屏东县|