Another Log to Analyze – Utilizing DNS to Discover Malware in Your Network

ShmooCon X - 2014

Presented by: Nathan Magniez
Date: Friday January 17, 2014
Time: 20:50 - 21:10
Location: Build It Room
Track: Fire Talks

DNS logs are an often overlooked asset in identifying malware in your network. The purpose of this talk is to identify malware in the network through establishing DNS query and response baselines, analysis of NXDOMAIN responses, analysis of successful DNS lookups, and identifying domain name anomalies. This talk will give you the basics of what to look for in your own unique environment.

Nathan Magniez

KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats