Date Author Title

DNS FORENSICS

2020-12-16Daniel WesemannDNS Logs in Public Clouds
2019-10-25Rob VandenBrinkMore on DNS Archeology (with PowerShell)

DNS

2024-09-25/a>Johannes UllrichDNS Reflection Update and Odd Corrupted DNS Requests
2024-08-30/a>Jesse La GrewSimulating Traffic With Scapy
2024-08-20/a>Guy BruneauMapping Threats with DNSTwist and the Internet Storm Center [Guest Diary]
2024-05-06/a>Johannes UllrichDetecting XFinity/Comcast DNS Spoofing
2024-01-31/a>Johannes UllrichThe Fun and Dangers of Top Level Domains (TLDs)
2023-11-07/a>Johannes UllrichWhat's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR)
2023-09-06/a>Johannes UllrichSecurity Relevant DNS Records
2023-08-01/a>Johannes UllrichSummary of DNS over HTTPS requests against our honeypots.
2023-02-15/a>Rob VandenBrinkDNS Recon Redux - Zone Transfers (plus a time machine) for When You Can't do a Zone Transfer
2023-01-30/a>Johannes UllrichDecoding DNS over HTTP(s) Requests
2023-01-23/a>Xavier MertensWho's Resolving This Domain?
2022-08-31/a>Johannes UllrichUnderscores and DNS: The Privacy Story
2022-08-10/a>Johannes UllrichAnd Here They Come Again: DNS Reflection Attacks
2022-04-29/a>Rob VandenBrinkUsing Passive DNS sources for Reconnaissance and Enumeration
2021-12-17/a>Rob VandenBrinkDR Automation - Using Public DNS APIs
2021-10-04/a>Johannes UllrichFacebook Outage: Yes, its DNS (sort of). A super quick analysis of what is going on.
2021-09-11/a>Guy BruneauShipping to Elasticsearch Microsoft DNS Logs
2021-07-31/a>Guy BruneauUnsolicited DNS Queries
2021-06-19/a>Xavier MertensEasy Access to the NIST RDS Database
2021-05-30/a>Didier StevensVideo: Cobalt Strike & DNS - Part 1
2021-05-20/a>Johannes UllrichNew YouTube Video Series: Everything you ever wanted to know about DNS and more!
2021-01-25/a>Rob VandenBrinkFun with NMAP NSE Scripts and DOH (DNS over HTTPS)
2021-01-15/a>Guy BruneauObfuscated DNS Queries
2020-12-16/a>Daniel WesemannDNS Logs in Public Clouds
2020-12-08/a>Johannes UllrichDecember 2020 Microsoft Patch Tuesday: Exchange, Sharepoint, Dynamics and DNS Spoofing
2020-10-30/a>Xavier MertensQuick Status of the CAA DNS Record Adoption
2020-08-04/a>Johannes UllrichInternet Choke Points: Concentration of Authoritative Name Servers
2020-07-16/a>John BambenekHunting for SigRed Exploitation
2020-07-15/a>Johannes UllrichPATCH NOW - SIGRed - CVE-2020-1350 - Microsoft DNS Server Vulnerability
2019-12-29/a>Guy BruneauELK Dashboard for Pihole Logs
2019-12-07/a>Guy BruneauIntegrating Pi-hole Logs in ELK with Logstash
2019-11-25/a>Xavier MertensMy Little DoH Setup
2019-10-25/a>Rob VandenBrinkMore on DNS Archeology (with PowerShell)
2019-10-21/a>Jim ClausingWhat's up with TCP 853 (DNS over TLS)?
2019-07-17/a>Xavier MertensAnalyzis of DNS TXT Records
2019-07-13/a>Guy BruneauGuidance to Protect DNS Against Hijacking & Scanning for Version.BIND Still a Thing
2019-07-09/a>John BambenekSolving the WHOIS and Privacy Problem: A Draft of Implementing WHOIS in DNS
2019-06-16/a>Didier StevensSysmon Version 10: DNS Logging
2019-03-27/a>Xavier MertensRunning your Own Passive DNS Service
2019-01-31/a>Xavier MertensTracking Unexpected DNS Changes
2019-01-22/a>Xavier MertensDNS Firewalling with MISP
2018-09-22/a>Didier StevensSuspicious DNS Requests ... Issued by a Firewall
2018-02-25/a>Guy BruneauBlackhole Advertising Sites with Pi-hole
2017-12-13/a>Xavier MertensTracking Newly Registered Domains
2017-11-16/a>Xavier MertensSuspicious Domains Tracking Dashboard
2017-10-20/a>Rick WannerOne year Anniversary of Dyn DDOS
2017-10-02/a>Xavier MertensInvestigating Security Incidents with Passive DNS
2017-06-14/a>Xavier MertensSystemd Could Fallback to Google DNS?
2017-04-20/a>Xavier MertensDNS Query Length... Because Size Does Matter
2016-10-23/a>Johannes UllrichISC Briefing: Large DDoS Attack Against Dyn
2016-07-26/a>Johannes UllrichCommand and Control Channels Using "AAAA" DNS Records
2016-06-12/a>Guy BruneauDNS Sinkhole ISO Version 2.0
2016-04-28/a>Rob VandenBrinkDNS and DHCP Recon using Powershell
2015-11-22/a>Guy BruneauOpenDNS Research Used to Predict Threat
2015-11-08/a>Rick WannerDNS Reconnaissance using nmap
2015-08-19/a>Bojan ZdrnjaOutsourcing critical infrastructure (such as DNS)
2015-02-19/a>Daniel WesemannDNS-based DDoS
2014-06-02/a>Rick WannerUsing nmap to scan for DDOS reflectors
2014-05-20/a>Johannes UllrichDetecting Queries to "odd" DNS Servers
2014-04-30/a>Johannes UllrichBe on the Lookout: Odd DNS Traffic, Possible C&C Traffic
2014-04-30/a>Russ McReeUltraDNS DDOS
2014-02-04/a>Johannes UllrichDo you block "new" domain names?
2014-01-30/a>Johannes UllrichNew gTLDs appearing in the root zone
2013-12-21/a>Guy BruneauStrange DNS Queries - Request for Packets
2013-11-19/a>Jim ClausingUpdated dumpdns.pl
2013-11-04/a>Manuel Humberto Santander PelaezWhen attackers use your DNS to check for the sites you are visiting
2013-10-21/a>Johannes UllrichNew tricks that may bring DNS spoofing back or: "Why you should enable DNSSEC even if it is a pain to do"
2013-10-17/a>Adrien de BeaupreInternet wide DNS scanning
2013-10-10/a>Johannes Ullrichgoogle.com.my DNS hijack
2013-10-08/a>Johannes UllrichCSAM: ANY queries used in reflective DoS attack
2013-10-02/a>Johannes UllrichCSAM: Misc. DNS Logs
2013-09-26/a>Johannes UllrichHow do you monitor DNS?
2013-09-02/a>Guy BruneauSnort IDS Sensor with Sguil New ISO Released
2013-08-14/a>Johannes Ullrich.GOV zones may not resolve due to DNSSEC problems.
2013-08-07/a>Mark HofmanDNS servers hijacked in the Netherlands
2013-07-17/a>Johannes UllrichNetwork Solutions Outage
2013-07-12/a>Johannes UllrichDNS resolution is failing for Microsofts Teredo server (teredo.ipv6.microsoft.com)
2013-07-10/a>Johannes Ullrich.NL Registrar Compromisse
2013-06-22/a>Guy Bruneau.biz DNSSEC DNSKEY is Invalid
2013-06-20/a>Johannes UllrichLinkedin DNS Hijack
2013-06-05/a>Richard PorterBIND 9 Update fixing CVE-2013-3919
2012-12-14/a>Johannes UllrichThe "D-root" DNS server (terp.umd.edu) is changing its IP address in January http://seclists.org/nanog/2012/Dec/330
2012-12-06/a>Daniel WesemannComodo DNS hiccup on usertrust.com
2012-08-16/a>Johannes UllrichA Poor Man's DNS Anomaly Detection Script
2012-07-24/a>Richard PorterReport of spike in DNS Queries gd21.net
2012-07-21/a>Rick WannerOpenDNS is looking for a few good malware people!
2012-07-21/a>Rick WannerTippingPoint DNS Version Request increase
2012-05-21/a>Kevin ShorttDNS ANY Request Cannon - Need More Packets
2012-05-16/a>Johannes UllrichGot Packets? Odd duplicate DNS replies from 10.x IP Addresses
2012-03-30/a>Daniel WesemannTomorrow, the world will end
2012-02-23/a>donald smithDNS-Changer "clean DNS" extension requested
2012-02-20/a>Rick WannerDNSChanger resolver shutdown deadline is March 8th
2012-02-09/a>Richard PorterDNS Ghost Domains, How I loath you so!
2012-01-21/a>Guy BruneauDNS Sinkhole Scripts Fixes/Update
2012-01-18/a>Johannes UllrichUse of Mixed Case DNS Queries
2012-01-13/a>Guy BruneauStrange DNS Queries - Request Packets/Logs
2011-12-13/a>Johannes UllrichPossible Widespread DNS Attack (info wanted)
2011-12-05/a>Stephen HallISC describe DNS crash bug analysis
2011-11-28/a>Tom ListonA Puzzlement...
2011-11-16/a>Jason LamPotential 0-day on Bind 9
2011-11-11/a>Rick WannerWhat's up with fbi.gov DNS?
2011-11-11/a>Johannes UllrichDetails About the fbi.gov DNSSEC Configuration Issue.
2011-11-09/a>Russ McReeOperation Ghost Click: FBI bags crime ring responsible for $14 million in losses
2011-10-15/a>Guy BruneauDNS Sinkhole Parser Script Update
2011-10-10/a>Tom ListonWhat's In A Name?
2011-09-09/a>Guy BruneauIPv6 and DNS Sinkhole
2011-09-04/a>Lorna HutchesonSeveral Sites Defaced
2011-08-17/a>Rob VandenBrinkWhen Good Patches go Bad - a DNS tale that didn't start out that way
2011-08-05/a>Johannes UllrichMicrosoft Patch Tuesday Advance Notification: 13 Bulletins coming http://www.microsoft.com/technet/security/Bulletin/MS11-aug.mspx
2011-08-05/a>donald smithNew Mac Trojan: BASH/QHost.WB
2011-07-05/a>Raul SilesTwo DoS remotely exploitable vulnerabilities affect BIND 9: http://www.isc.org/advisories/bind Updgrade to 9.8.0-P4.
2011-06-28/a>Johannes UllrichDNSSEC Tips
2011-06-03/a>Guy BruneauNew Poll: How are you dealing with Malicious Domains?
2011-05-09/a>Johannes UllrichPatch for BIND 9.8.0 DoS Vulnerability
2011-04-14/a>Johannes Ullrichdshield.org now DNSSEC signed via .org
2011-04-05/a>Mark HofmanDNS.be DDOS
2011-01-26/a>Bojan ZdrnjaGoogle Chrome and (weird) DNS requests
2010-11-25/a>Bojan ZdrnjaSecunia's DNS/domain hijacked?
2010-11-13/a>Guy BruneauRegister.com DNS Issues
2010-11-04/a>Johannes UllrichDNSSEC Progress for .com and .net
2010-10-03/a>Adrien de BeaupreH went down.
2010-09-25/a>Rick WannerGuest Diary: Andrew Hunt - Visualizing the Hosting Patterns of Modern Cybercriminals
2010-08-07/a>Stephen HallDnsMadeEasy under a "quite large and unique" ddos.
2010-07-29/a>Rob VandenBrinkNoScript 2.0 released
2010-06-19/a>Guy BruneauDNS Sinkhole ISO Available for Download
2010-05-12/a>Johannes Ullrich.de TLD Outage
2010-05-04/a>Rick WannerDNSSEC...not a bang but a whimper?
2010-02-26/a>Rick WannerNew version of dnsmap
2010-01-19/a>Jim Clausing49Gbps DDoS, IPv4 exhaustion, and DNSSEC, oh my!
2010-01-12/a>Johannes UllrichBaidu defaced - Domain Registrar Tampering
2010-01-11/a>Johannes Ullrichthe (large) domain registrar "eNom" appears to have problems with its DNS servers according to some user reports.
2010-01-10/a>Guy BruneauEasy DNS BIND Sinkhole Setup
2009-12-15/a>Johannes UllrichImportant BIND name server updates - DNSSEC
2009-11-25/a>Jim ClausingUpdates to my GREM Gold scripts and a new script
2009-11-24/a>John BambenekBIND Security Advisory (DNSSEC only)
2009-11-02/a>Daniel WesemannIDN ccTLDs
2009-10-29/a>Kyle HaugsnessCyber Security Awareness Month - Day 29 - dns port 53
2009-07-29/a>Bojan ZdrnjaBIND 9 DoS attacks in the wild
2009-04-26/a>Johannes UllrichOdd DNS Resolution for Google via OpenDNS
2009-03-21/a>Stephen HallUpdates to ISC BIND
2009-01-31/a>Swa FrantzenDNS DDoS - let's use a long term solution
2009-01-18/a>Daniel WesemannDNS queries for "."
2009-01-08/a>Kyle HaugsnessBIND OpenSSL follow-up
2009-01-07/a>William SaluskyBIND 9.x security patch - resolves potentially new DNS poisoning vector
2008-12-04/a>Bojan ZdrnjaRogue DHCP servers
2008-11-25/a>Andre LudwigOS X Dns Changers part three
2008-11-25/a>Andre LudwigTmobile G1 handsets having DNS problems?
2008-10-17/a>Patrick NolanDay 17 - Containing a DNS Hijacking
2008-10-08/a>Johannes UllrichDomaincontrol (GoDaddy) Nameservers DNS Poisoning
2008-08-14/a>Johannes UllrichDNSSEC for DShield.org
2008-08-05/a>Daniel WesemannWatching those DNS logs
2008-08-02/a>Swa FrantzenBIND: -P2 patches are released
2008-07-25/a>Swa FrantzenDNS bug - observations
2008-07-24/a>Kyle HaugsnessDNS cache poisoning vulnerability details confirmed
2008-07-22/a>Swa FrantzenDan Kaminsky's DNS bug: revealed? - Patch!
2008-07-09/a>Marcus SachsDNS Vulnerability Found by a GSEC Student Three Years Ago!
2008-07-08/a>Johannes UllrichMulitple Vendors DNS Spoofing Vulnerability
2008-05-19/a>Maarten Van HorenbeeckRoute filtering and its impact on the DNS fabric
2008-04-30/a>Bojan Zdrnja(Minor) evolution in Mac DNS changer malware
2008-03-23/a>Johannes UllrichFinding hidden gems (easter eggs) in your logs (packet challenge!)

FORENSICS

2024-05-08/a>Xavier MertensAnalyzing Synology Disks on Linux
2024-03-29/a>Xavier MertensQuick Forensics Analysis of Apache logs
2023-01-26/a>Tom WebbLive Linux IR with UAC
2021-11-04/a>Tom WebbXmount for Disk Images
2021-06-18/a>Daniel WesemannNetwork Forensics on Azure VMs (Part #2)
2021-06-17/a>Daniel Wesemann Network Forensics on Azure VMs (Part #1)
2021-02-25/a>Daniel WesemannForensicating Azure VMs
2020-12-16/a>Daniel WesemannDNS Logs in Public Clouds
2019-10-25/a>Rob VandenBrinkMore on DNS Archeology (with PowerShell)
2019-08-21/a>Russ McReeKAPE: Kroll Artifact Parser and Extractor
2018-01-26/a>Xavier MertensInvestigating Microsoft BITS Activity
2017-10-02/a>Xavier MertensInvestigating Security Incidents with Passive DNS
2017-09-24/a>Jim ClausingForensic use of mount --bind
2017-09-19/a>Jim ClausingNew tool: mac-robber.py
2017-07-09/a>Russ McReeAdversary hunting with SOF-ELK
2017-01-12/a>Mark BaggettSystem Resource Utilization Monitor
2016-10-31/a>Russ McReeSEC505 DFIR capture script: snapshot.ps1
2016-08-11/a>Pasquale StirparoLooking for the insider: Forensic Artifacts on iOS Messaging App
2016-05-22/a>Pasquale StirparoThe strange case of WinZip MRU Registry key
2016-03-28/a>Xavier MertensImproving Bash Forensics Capabilities
2016-03-11/a>Jim ClausingForensicating Docker, Part 1
2016-02-18/a>Xavier MertensHunting for Executable Code in Windows Environments
2016-01-06/a>Russ McReetoolsmith #112: Red vs Blue - PowerSploit vs PowerForensics
2015-04-24/a>Basil Alawi S.TaherFileless Malware
2015-04-17/a>Didier StevensMemory Forensics Of Network Devices
2015-03-18/a>Daniel WesemannNew SANS memory forensics poster
2015-02-03/a>Johannes UllrichAnother Network Forensic Tool for the Toolbox - Dshell
2014-08-10/a>Basil Alawi S.TaherIncident Response with Triage-ir
2014-06-22/a>Russ McReeOfficeMalScanner helps identify the source of a compromise
2014-06-03/a>Basil Alawi S.TaherAn Introduction to RSA Netwitness Investigator
2014-05-18/a>Russ McReesed and awk will always rock
2014-03-11/a>Basil Alawi S.TaherIntroduction to Memory Analysis with Mandiant Redline
2014-03-07/a>Tom WebbLinux Memory Dump with Rekall
2014-02-09/a>Basil Alawi S.TaherMandiant Highlighter 2
2014-01-10/a>Basil Alawi S.TaherWindows Autorun-3
2013-12-12/a>Basil Alawi S.TaherAcquiring Memory Images with Dumpit
2013-11-21/a>Mark Baggett"In the end it is all PEEKS and POKES."
2013-11-20/a>Mark BaggettSearching live memory on a running machine with winpmem
2013-11-19/a>Mark BaggettWinpmem - Mild mannered memory aquisition tool??
2013-08-26/a>Alex StanfordStop, Drop and File Carve
2013-08-14/a>Johannes UllrichImaging LUKS Encrypted Drives
2013-07-12/a>Rob VandenBrinkHmm - where did I save those files?
2013-05-23/a>Adrien de BeaupreMoVP II
2013-04-25/a>Adam SwangerSANS 2013 Forensics Survey - https://www.surveymonkey.com/s/2013SANSForensicsSurvey
2012-11-02/a>Daniel WesemannThe shortcomings of anti-virus software
2012-09-14/a>Lenny ZeltserAnalyzing Malicious RTF Files Using OfficeMalScanner's RTFScan
2012-06-04/a>Lenny ZeltserDecoding Common XOR Obfuscation in Malicious Code
2011-09-29/a>Daniel WesemannThe SSD dilemma
2011-08-05/a>Johannes UllrichForensics: SIFT Kit 2.1 now available for download http://computer-forensics.sans.org/community/downloads
2011-03-01/a>Daniel WesemannAV software and "sharing samples"
2010-11-17/a>Guy BruneauReference on Open Source Digital Forensics
2010-05-22/a>Rick WannerSANS 2010 Digital Forensics Summit - APT Based Forensic Challenge
2010-05-21/a>Rick Wanner2010 Digital Forensics and Incident Response Summit
2010-04-30/a>Kevin ListonThe Importance of Small Files
2010-04-11/a>Marcus SachsNetwork and process forensics toolset
2010-03-26/a>Daniel WesemannSIFT2.0 SANS Investigative Forensics Toolkit released
2009-12-14/a>Adrien de BeaupreAnti-forensics, COFEE vs. DECAF
2009-11-25/a>Jim ClausingUpdates to my GREM Gold scripts and a new script
2009-08-18/a>Daniel WesemannForensics: Mounting partitions from full-disk 'dd' images
2009-08-13/a>Jim ClausingNew and updated cheat sheets
2009-07-02/a>Daniel WesemannGetting the EXE out of the RTF
2009-02-02/a>Stephen HallHow do you audit your production code?
2009-01-02/a>Rick WannerTools on my Christmas list.
2008-11-17/a>Marcus SachsNew Tool: NetWitness Investigator
2008-08-17/a>Kevin ListonVolatility 1.3 Released
2008-08-15/a>Jim ClausingOMFW 2008 reflections