ConceptsDNS-Based Detection

DNS-Based Detection

Detection techniques that use DNS query data to find threats, spotting lookups of malicious, newly registered, or algorithmically generated domains, beaconing patterns, and DNS tunneling, often written as SIEM queries over DNS logs.

9 direct links5 lessons

Concept Neighborhood

Related Lessons

5 lessons cover this concept

Sign in to open lesson content directly.