官术网_书友最值得收藏!

DNS servers logs

Name server query logs can help understand IP-to-hostname resolution at specific times. Consider a scenario where, as soon as a system got infected with malware on the network, it tried to connect back to a certain domain for command and control. Let's see an example as follows:

We can see in the preceding screenshot that a DNS request was resolved for malwaresamples.com website and the resolved IP address was returned.

Having access to the DNS query packets can reveal Indicators of Compromise for a particular malware on the network while quickly revealing the IP address of the system making the query, and can be dealt with ease.

主站蜘蛛池模板: 土默特左旗| 皮山县| 牙克石市| 乌拉特后旗| 昔阳县| 荔波县| 长丰县| 五大连池市| 高陵县| 清水河县| 云霄县| 鄂托克旗| 集贤县| 新郑市| 竹溪县| 巢湖市| 新蔡县| 项城市| 肇东市| 绥棱县| 剑河县| 金华市| 桃源县| 德令哈市| 宜章县| 梁河县| 大丰市| 武邑县| 英山县| 陆丰市| 嵩明县| 筠连县| 翁源县| 永福县| 太原市| 阳泉市| 改则县| 西畴县| 驻马店市| 建始县| 明星|