logo

Threat Hunting: DNS Queries Use Case

ID: b5263d2f-fa86-5bb8-aa0c-0e541d6051c0

STIX ID: report--b5263d2f-fa86-5bb8-aa0c-0e541d6051c0

Feed Name: ReliaQuest Blog

Date Published: 2021-08-16

Date Updated: 2026-04-29

...
...

This threat-hunting use case describes a 30-day DNS query analysis workflow to baseline normal domain activity and detect threats such as DNS tunneling, DGAs, and suspicious TLD usage. It outlines log-source requirements, related MITRE techniques, and practical detection heuristics (e.g., uncommon RR types, high NXDOMAIN rates, many subdomains of one domain, long/high-entropy queries, and unusual processes) to help defenders identify and investigate malicious DNS behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.