data:image/s3,"s3://crabby-images/bd587/bd587a85307a3355b7b70d69f2fdb9c47c54a7bc" alt="Hands-On Network Forensics"
上QQ阅读APP看书,第一时间看更新
DNS servers logs
Name server query logs can help understand IP-to-hostname resolution at specific times. Consider a scenario where, as soon as a system got infected with malware on the network, it tried to connect back to a certain domain for command and control. Let's see an example as follows:
data:image/s3,"s3://crabby-images/5a5fa/5a5fa98c2b8666f973558543041c94d5c755306c" alt=""
We can see in the preceding screenshot that a DNS request was resolved for malwaresamples.com website and the resolved IP address was returned.
Having access to the DNS query packets can reveal Indicators of Compromise for a particular malware on the network while quickly revealing the IP address of the system making the query, and can be dealt with ease.