Add Punycode to your Threat Hunting Routine, (Tue, Jan 20th)
ID: 7a10cd5d-218b-5509-88c7-9d72e8e9dac6
STIX ID: report--7a10cd5d-218b-5509-88c7-9d72e8e9dac6
Feed Name: SANS ISC Diary
The report explains how Internationalized Domain Names (IDNs) and Punycode enable homograph attacks that mimic legitimate domains, then demonstrates how to detect such abuse by searching DNS resolver logs for the xn-- prefix and decoding suspicious domains (e.g., with Python), emphasizing DNS as a valuable source for threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
