Threat Hunting via DNS | SANS@MIC Talk

Поділитися
Вставка
  • Опубліковано 17 лис 2024

КОМЕНТАРІ • 15

  • @gitgudsec
    @gitgudsec Рік тому

    Also just wanna thank Eric; yourself, John Strand and Chris Benton are imo the best teachers out there 🙏🏻

  • @SteveWray
    @SteveWray 2 роки тому

    Something that I noticed is that DNS recon can be fairly easy to spot and I don't think any of the encryption methods would hide it, if you own the authoritative nameservers and can log from them. I used Elasticsearch' packetbeat on the nameserver, thereby avoiding the DNS servers logging limitations.

  • @gitgudsec
    @gitgudsec Рік тому

    Sorry if this is moronic - but can companies not just institutionalize a policy where all internal network dns is do53, and then only translates to doh at the egress? And vice-versa? I know there is obvs something preventing this, can someone smarter than me please help me out?

  • @zackthomas5707
    @zackthomas5707 4 роки тому

    Really enjoyed this and learned a ton. Subscribed and thanks for sharing this knowledge.

    • @kyreeforest4868
      @kyreeforest4868 3 роки тому

      i dont mean to be so offtopic but does any of you know a method to log back into an Instagram account..?
      I stupidly lost the login password. I would love any assistance you can offer me.

    • @gannonjedidiah3198
      @gannonjedidiah3198 3 роки тому

      @Kyree Forest Instablaster ;)

    • @kyreeforest4868
      @kyreeforest4868 3 роки тому

      @Gannon Jedidiah thanks for your reply. I got to the site on google and Im trying it out now.
      Seems to take a while so I will reply here later with my results.

    • @kyreeforest4868
      @kyreeforest4868 3 роки тому

      @Gannon Jedidiah it worked and I finally got access to my account again. I'm so happy:D
      Thank you so much you saved my ass :D

    • @gannonjedidiah3198
      @gannonjedidiah3198 3 роки тому

      @Kyree Forest Happy to help xD

  • @GilligansTravels
    @GilligansTravels 4 роки тому

    awesome!

  • @Qantum802
    @Qantum802 Рік тому

    🙂 cool

  • @jum5238
    @jum5238 4 роки тому

    Is it possible to point to the slides directly in the details area above?

    • @ericconrad5783
      @ericconrad5783 4 роки тому

      www.ericconrad.com/2020/03/threat-hunting-via-dns.html

    • @jum5238
      @jum5238 4 роки тому

      @@ericconrad5783 Thank you, Eric. But unless I'm missing something, these are the links WITHIN the presentation, not the slides themselves.

    • @ericconrad5783
      @ericconrad5783 4 роки тому +1

      @@jum5238 Click on the "Threat Hunting via DNS" hyperlink to see the slides