logo

Tracing DNS Queries on Your Windows DNS Server

ID: ee4c3a99-5bea-59e3-8730-e317a036ac0e

STIX ID: report--ee4c3a99-5bea-59e3-8730-e317a036ac0e

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report documents a practical attack and detection workflow where an attacker deployed a wildcard DNS record and used Responder to poison DNS lookups, resulting in domain compromise of a privileged account; it then walks through enabling Windows Server DNS debug logging (Server 2012+), capturing and parsing detailed DNS traces, and using a PowerShell parser to identify hosts querying for non-existent records that were resolved to a chosen wildcard IP. The post includes operational cautions about logging impact, recommends choosing a unique wildcard IP, and suggests follow-up steps such as enabling Sysmon DNS query logging and feeding summarized logs to a SIEM for ongoing detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.