DNS is one of the most information-rich network signals available. Command-and-control malware uses DNS to communicate with its operators. Data exfiltration can be encoded in DNS queries. Lateral movement generates characteristic DNS lookup patterns. Many organisations monitor HTTP traffic but leave DNS unmonitored. Deploy DNS security services (Cisco Umbrella, Cloudflare Gateway, or a self-hosted resolver with logging) and configure alerts for: newly registered domains, unusual query volumes, queries for domains with high entropy names (DGA indicators), and DNS-over-HTTPS to unexpected resolvers.
Tags