logo

Threat Hunting Use Case: Firewall Targeting DNS

ID: 446f69c1-b4d4-5d00-bc8a-289d95c5c020

STIX ID: report--446f69c1-b4d4-5d00-bc8a-289d95c5c020

Feed Name: ReliaQuest Blog

Date Published: 2020-08-26

Date Updated: 2026-04-29

...
...

**Firewall Targeting DNS – Threat Hunting Use Case**: This blog post describes a threat-hunting use case that reviews firewall DNS traffic to detect and remediate risks such as DNS-based exfiltration (mapped to MITRE techniques T1048 and T1571), outlines log source requirements (application/protocol-aware firewall allow/deny logs), suggested 30–90 day duration, baseline/hygiene checks, and threat analysis steps (uncommon port usage, geo/IP filtering, large outbound flows, OSINT correlation), and recommends restricting outbound DNS (port 53) to authorized resolvers and improving firewall rule granularity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.