logo

Why Do Incident Responders and Other Investigators Focus on Particular DNS Record Types?

ID: 29a9a0e6-70b3-5a24-98eb-f3a2b952d55e

STIX ID: report--29a9a0e6-70b3-5a24-98eb-f3a2b952d55e

Feed Name: DomainTools

Date Published: 2026-02-22

Date Updated: 2026-04-27

Author: domaintools.com

...
...

**Executive Summary:** This blog post explains how analysts leverage passive DNS (DNSDB) to prioritize and pivot on DNS record types—primarily A/AAAA/CNAME and NS—illustrating common investigative workflows (wildcard domain searches, IP-to-name pivots, NS-based lateral pivots), command examples (dnsdbq and jq), and notable indicators that draw attention (algorithmic/random-looking domains, unusually large SPF CIDR ranges, use of NULL records for tunneling), with a reminder to explicitly query DNSSEC records when needed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.