Slow DNS Reflection (DGA Domains or Domain Fluxing)
11
Bad Query Name Format
12
Malformed DNS Packets
13
DNS Data Exfiltration
14
The Log Analysis Process
15
Log Shipping
16
TCL GELF Logging
17
Elasticsearch
18
Malicious Source IPs
19
Network Compromise
20
AD DNS Debug Data
21
Device Compromise
22
DNS Query Response Codes
23
Securing AD DNS
24
AD DNS Debug Logging
25
Securing DNS
Description:
Explore the dark side of DNS in this 40-minute conference talk from CircleCityCon 2017. Delve into DNS resolution processes, key terminology, and common server software. Learn to use Dig and Wireshark for DNS analysis. Examine various DNS-based attacks, including amplification, slow reflection, and data exfiltration. Discover log analysis techniques, including log shipping and Elasticsearch. Investigate malicious activities through DNS query response codes and AD DNS debug data. Gain insights on securing Active Directory DNS and implementing effective DNS debug logging for enhanced network security.
DNS Dark Matter Discovery - Theres Evil In Those Queries