官术网_书友最值得收藏!

DNS servers logs

Name server query logs can help understand IP-to-hostname resolution at specific times. Consider a scenario where, as soon as a system got infected with malware on the network, it tried to connect back to a certain domain for command and control. Let's see an example as follows:

We can see in the preceding screenshot that a DNS request was resolved for malwaresamples.com website and the resolved IP address was returned.

Having access to the DNS query packets can reveal Indicators of Compromise for a particular malware on the network while quickly revealing the IP address of the system making the query, and can be dealt with ease.

主站蜘蛛池模板: 蒙自县| 广南县| 扎囊县| 黄浦区| 白银市| 随州市| 刚察县| 承德市| 石嘴山市| 延川县| 呼和浩特市| 辉南县| 金山区| 阿鲁科尔沁旗| 民县| 塔城市| 岐山县| 中山市| 大丰市| 芜湖县| 阳东县| 柘城县| 铅山县| 含山县| 定远县| 上思县| 九江市| 奉化市| 当雄县| 鸡西市| 龙井市| 临邑县| 日土县| 五原县| 博爱县| 普兰县| 屏东县| 海门市| 庆云县| 涟水县| 广昌县|