Something that I noticed is that DNS recon can be fairly easy to spot and I don't think any of the encryption methods would hide it, if you own the authoritative nameservers and can log from them. I used Elasticsearch' packetbeat on the nameserver, thereby avoiding the DNS servers logging limitations.
Sorry if this is moronic - but can companies not just institutionalize a policy where all internal network dns is do53, and then only translates to doh at the egress? And vice-versa? I know there is obvs something preventing this, can someone smarter than me please help me out?
i dont mean to be so offtopic but does any of you know a method to log back into an Instagram account..? I stupidly lost the login password. I would love any assistance you can offer me.
@Gannon Jedidiah thanks for your reply. I got to the site on google and Im trying it out now. Seems to take a while so I will reply here later with my results.
Also just wanna thank Eric; yourself, John Strand and Chris Benton are imo the best teachers out there 🙏🏻
Something that I noticed is that DNS recon can be fairly easy to spot and I don't think any of the encryption methods would hide it, if you own the authoritative nameservers and can log from them. I used Elasticsearch' packetbeat on the nameserver, thereby avoiding the DNS servers logging limitations.
Sorry if this is moronic - but can companies not just institutionalize a policy where all internal network dns is do53, and then only translates to doh at the egress? And vice-versa? I know there is obvs something preventing this, can someone smarter than me please help me out?
Really enjoyed this and learned a ton. Subscribed and thanks for sharing this knowledge.
i dont mean to be so offtopic but does any of you know a method to log back into an Instagram account..?
I stupidly lost the login password. I would love any assistance you can offer me.
@Kyree Forest Instablaster ;)
@Gannon Jedidiah thanks for your reply. I got to the site on google and Im trying it out now.
Seems to take a while so I will reply here later with my results.
@Gannon Jedidiah it worked and I finally got access to my account again. I'm so happy:D
Thank you so much you saved my ass :D
@Kyree Forest Happy to help xD
awesome!
🙂 cool
Is it possible to point to the slides directly in the details area above?
www.ericconrad.com/2020/03/threat-hunting-via-dns.html
@@ericconrad5783 Thank you, Eric. But unless I'm missing something, these are the links WITHIN the presentation, not the slides themselves.
@@jum5238 Click on the "Threat Hunting via DNS" hyperlink to see the slides