DNS-Based Detection
Detection techniques that use DNS query data to find threats, spotting lookups of malicious, newly registered, or algorithmically generated domains, beaconing patterns, and DNS tunneling, often written as SIEM queries over DNS logs.
Concept Neighborhood
Explore this concept’s connections in the groups below.
Start here
DNS Logs
The foundation DNS-Based Detection builds on, worth understanding first.
DNS LogsStart here
Records of DNS queries and responses, capturing which domains hosts looked up and when. They are a high-value telemetry source for detecting malware, command-and-control, data exfiltration, and suspicious domains.
6
lessons
Baseline Analysis
Establishing what normal activity looks like in an environment so that deviations stand out as worth investigating. In detection and SIEM work, the baseline is the reference against which anomalies are measured.
5
lessons
Detection Coverage
6
lessons
First-Seen Detection
5
lessons
Kusto Query Language
5
lessons
TLD
3
lessons
MX Record
1
lesson
Resolver
1
lesson
Show 1 more connection
Related Lessons
5 lessons cover this conceptSIEM Data Models and Log Normalization
SOC Analyst
Aggregation and Statistical Analysis for Threat Detection
SOC Analyst
Time-Series Analysis and Multi-Source Correlation
SOC Analyst
Query Tuning, Lookup Tables, and Production Operations
SOC Analyst
Designing a Detection Program with SIEM Queries
SOC Analyst
Sign in to open lesson content directly.
