Terminology Index
Glossary
1801 terms
Showing 481-512 of 1801 terms
DNS
DNS is the naming system that translates domain names into network addresses and related records.
DNS-Based Detection
Detection techniques that use DNS query data to find threats, spotting lookups of malicious, newly registered, or algorithmically generated domains, beaconing patterns, and DNS tunneling, often written as SIEM queries over DNS logs.
Because almost all activity begins with a DNS lookup, DNS-based detection is a powerful, high-coverage approach: detections flag queries to known-bad domains, domains generated by malware algorithms (DGA), suspicious volumes suggesting tunneling, and first-seen or rare domains. Built as SIEM queries over DNS logs and tuned against a baseline, these detections catch command-and-control and exfiltration that other telemetry might miss.
Introduced in: SIEM Query Fundamentals
Examples
- Alerting on queries to algorithmically generated (DGA) domains.
- Detecting DNS tunneling from anomalous query size and frequency.
- Flagging first-seen or rare domains against a baseline of normal lookups.
No related terms linked yet.
