Skip to content

dns

AV <-> E(X)DR again…

Some time ago, I wrote an article about the differences between AV and E/XDR products. I have another good example that shows why AV products are obsolete. In my previous blog post, I described a DNS tunneling technique used for C2 communication. This article shows how the same activity looks from the host detection perspective.… Read More »AV <-> E(X)DR again…

DNS Tunneling again…

Some time ago, I did some tests related to DNS tunneling identification. What was wrong with that scenario was that the test was not based on a real-life setup. DNS tunneling happened only inside the infrastructure (LAN environment), without any connection to the Internet or external DNS servers. Such a scenario can influence how vendors… Read More »DNS Tunneling again…

DNS Sinkhole

Two weeks ago I wrote blog post about importance of DNS visibility – https://letsnet.eu/dns-over-tls-dns-over-https/. Let’s assume that DNS traffic is properly inspected, queries to malicious domains can be seen and you have capabilities to identify DNS tunneling and to block it as well. Is blocking a proper action to malicious DNS queries? Not really, let’s… Read More »DNS Sinkhole