Threat Hunting: DNS Queries Use Case
ID: b5263d2f-fa86-5bb8-aa0c-0e541d6051c0
STIX ID: report--b5263d2f-fa86-5bb8-aa0c-0e541d6051c0
Feed Name: ReliaQuest Blog
This threat-hunting use case describes a 30-day DNS query analysis workflow to baseline normal domain activity and detect threats such as DNS tunneling, DGAs, and suspicious TLD usage. It outlines log-source requirements, related MITRE techniques, and practical detection heuristics (e.g., uncommon RR types, high NXDOMAIN rates, many subdomains of one domain, long/high-entropy queries, and unusual processes) to help defenders identify and investigate malicious DNS behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
