Tracing DNS Queries on Your Windows DNS Server
ID: ee4c3a99-5bea-59e3-8730-e317a036ac0e
STIX ID: report--ee4c3a99-5bea-59e3-8730-e317a036ac0e
Feed Name: TrustedSec blog
This report documents a practical attack and detection workflow where an attacker deployed a wildcard DNS record and used Responder to poison DNS lookups, resulting in domain compromise of a privileged account; it then walks through enabling Windows Server DNS debug logging (Server 2012+), capturing and parsing detailed DNS traces, and using a PowerShell parser to identify hosts querying for non-existent records that were resolved to a chosen wildcard IP. The post includes operational cautions about logging impact, recommends choosing a unique wildcard IP, and suggests follow-up steps such as enabling Sysmon DNS query logging and feeding summarized logs to a SIEM for ongoing detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
