Threat Hunting with DNS Domain Names Collected from All Over Your Network

5/31/2018 12:00:00 PM [(UTC-05:00) Eastern Time (US & Canada)] - Can't make the live event? Register anyway to receive a link to the recording.

Show/Hide All Time Zones

All Time Zones

Dateline Standard Time-(UTC-12:00) International Date Line West 5/31/2018 4:00:00 AM
UTC-11-(UTC-11:00) Coordinated Universal Time-11 5/31/2018 5:00:00 AM
Aleutian Standard Time-(UTC-10:00) Aleutian Islands 5/31/2018 7:00:00 AM
Hawaiian Standard Time-(UTC-10:00) Hawaii 5/31/2018 6:00:00 AM
Marquesas Standard Time-(UTC-09:30) Marquesas Islands 5/31/2018 6:30:00 AM
Alaskan Standard Time-(UTC-09:00) Alaska 5/31/2018 8:00:00 AM
UTC-09-(UTC-09:00) Coordinated Universal Time-09 5/31/2018 7:00:00 AM
Pacific Standard Time (Mexico)-(UTC-08:00) Baja California 5/31/2018 9:00:00 AM
UTC-08-(UTC-08:00) Coordinated Universal Time-08 5/31/2018 8:00:00 AM
Pacific Standard Time-(UTC-08:00) Pacific Time (US & Canada) 5/31/2018 9:00:00 AM
US Mountain Standard Time-(UTC-07:00) Arizona 5/31/2018 9:00:00 AM
Mountain Standard Time (Mexico)-(UTC-07:00) Chihuahua, La Paz, Mazatlan 5/31/2018 10:00:00 AM
Mountain Standard Time-(UTC-07:00) Mountain Time (US & Canada) 5/31/2018 10:00:00 AM
Central America Standard Time-(UTC-06:00) Central America 5/31/2018 10:00:00 AM
Central Standard Time-(UTC-06:00) Central Time (US & Canada) 5/31/2018 11:00:00 AM
Easter Island Standard Time-(UTC-06:00) Easter Island 5/31/2018 10:00:00 AM
Central Standard Time (Mexico)-(UTC-06:00) Guadalajara, Mexico City, Monterrey 5/31/2018 11:00:00 AM
Canada Central Standard Time-(UTC-06:00) Saskatchewan 5/31/2018 10:00:00 AM
SA Pacific Standard Time-(UTC-05:00) Bogota, Lima, Quito, Rio Branco 5/31/2018 11:00:00 AM
Eastern Standard Time (Mexico)-(UTC-05:00) Chetumal 5/31/2018 11:00:00 AM
Eastern Standard Time-(UTC-05:00) Eastern Time (US & Canada) 5/31/2018 12:00:00 PM
Haiti Standard Time-(UTC-05:00) Haiti 5/31/2018 12:00:00 PM
Cuba Standard Time-(UTC-05:00) Havana 5/31/2018 12:00:00 PM
US Eastern Standard Time-(UTC-05:00) Indiana (East) 5/31/2018 12:00:00 PM
Turks And Caicos Standard Time-(UTC-05:00) Turks and Caicos 5/31/2018 12:00:00 PM
Paraguay Standard Time-(UTC-04:00) Asuncion 5/31/2018 12:00:00 PM
Atlantic Standard Time-(UTC-04:00) Atlantic Time (Canada) 5/31/2018 1:00:00 PM
Venezuela Standard Time-(UTC-04:00) Caracas 5/31/2018 12:00:00 PM
Central Brazilian Standard Time-(UTC-04:00) Cuiaba 5/31/2018 12:00:00 PM
SA Western Standard Time-(UTC-04:00) Georgetown, La Paz, Manaus, San Juan 5/31/2018 12:00:00 PM
Pacific SA Standard Time-(UTC-04:00) Santiago 5/31/2018 12:00:00 PM
Newfoundland Standard Time-(UTC-03:30) Newfoundland 5/31/2018 1:30:00 PM
Tocantins Standard Time-(UTC-03:00) Araguaina 5/31/2018 1:00:00 PM
E. South America Standard Time-(UTC-03:00) Brasilia 5/31/2018 1:00:00 PM
SA Eastern Standard Time-(UTC-03:00) Cayenne, Fortaleza 5/31/2018 1:00:00 PM
Argentina Standard Time-(UTC-03:00) City of Buenos Aires 5/31/2018 1:00:00 PM
Greenland Standard Time-(UTC-03:00) Greenland 5/31/2018 2:00:00 PM
Montevideo Standard Time-(UTC-03:00) Montevideo 5/31/2018 1:00:00 PM
Magallanes Standard Time-(UTC-03:00) Punta Arenas 5/31/2018 1:00:00 PM
Saint Pierre Standard Time-(UTC-03:00) Saint Pierre and Miquelon 5/31/2018 2:00:00 PM
Bahia Standard Time-(UTC-03:00) Salvador 5/31/2018 1:00:00 PM
UTC-02-(UTC-02:00) Coordinated Universal Time-02 5/31/2018 2:00:00 PM
Mid-Atlantic Standard Time-(UTC-02:00) Mid-Atlantic - Old 5/31/2018 3:00:00 PM
Azores Standard Time-(UTC-01:00) Azores 5/31/2018 4:00:00 PM
Cape Verde Standard Time-(UTC-01:00) Cabo Verde Is. 5/31/2018 3:00:00 PM
UTC-(UTC) Coordinated Universal Time 5/31/2018 4:00:00 PM
Morocco Standard Time-(UTC+00:00) Casablanca 5/31/2018 4:00:00 PM
GMT Standard Time-(UTC+00:00) Dublin, Edinburgh, Lisbon, London 5/31/2018 5:00:00 PM
Greenwich Standard Time-(UTC+00:00) Monrovia, Reykjavik 5/31/2018 4:00:00 PM
W. Europe Standard Time-(UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna 5/31/2018 6:00:00 PM
Central Europe Standard Time-(UTC+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague 5/31/2018 6:00:00 PM
Romance Standard Time-(UTC+01:00) Brussels, Copenhagen, Madrid, Paris 5/31/2018 6:00:00 PM
Sao Tome Standard Time-(UTC+01:00) Sao Tome 5/31/2018 5:00:00 PM
Central European Standard Time-(UTC+01:00) Sarajevo, Skopje, Warsaw, Zagreb 5/31/2018 6:00:00 PM
W. Central Africa Standard Time-(UTC+01:00) West Central Africa 5/31/2018 5:00:00 PM
Jordan Standard Time-(UTC+02:00) Amman 5/31/2018 7:00:00 PM
GTB Standard Time-(UTC+02:00) Athens, Bucharest 5/31/2018 7:00:00 PM
Middle East Standard Time-(UTC+02:00) Beirut 5/31/2018 7:00:00 PM
Egypt Standard Time-(UTC+02:00) Cairo 5/31/2018 6:00:00 PM
E. Europe Standard Time-(UTC+02:00) Chisinau 5/31/2018 7:00:00 PM
Syria Standard Time-(UTC+02:00) Damascus 5/31/2018 7:00:00 PM
West Bank Standard Time-(UTC+02:00) Gaza, Hebron 5/31/2018 7:00:00 PM
South Africa Standard Time-(UTC+02:00) Harare, Pretoria 5/31/2018 6:00:00 PM
FLE Standard Time-(UTC+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius 5/31/2018 7:00:00 PM
Israel Standard Time-(UTC+02:00) Jerusalem 5/31/2018 7:00:00 PM
Kaliningrad Standard Time-(UTC+02:00) Kaliningrad 5/31/2018 6:00:00 PM
Sudan Standard Time-(UTC+02:00) Khartoum 5/31/2018 6:00:00 PM
Libya Standard Time-(UTC+02:00) Tripoli 5/31/2018 6:00:00 PM
Namibia Standard Time-(UTC+02:00) Windhoek 5/31/2018 6:00:00 PM
Arabic Standard Time-(UTC+03:00) Baghdad 5/31/2018 7:00:00 PM
Turkey Standard Time-(UTC+03:00) Istanbul 5/31/2018 7:00:00 PM
Arab Standard Time-(UTC+03:00) Kuwait, Riyadh 5/31/2018 7:00:00 PM
Belarus Standard Time-(UTC+03:00) Minsk 5/31/2018 7:00:00 PM
Russian Standard Time-(UTC+03:00) Moscow, St. Petersburg, Volgograd 5/31/2018 7:00:00 PM
E. Africa Standard Time-(UTC+03:00) Nairobi 5/31/2018 7:00:00 PM
Iran Standard Time-(UTC+03:30) Tehran 5/31/2018 8:30:00 PM
Arabian Standard Time-(UTC+04:00) Abu Dhabi, Muscat 5/31/2018 8:00:00 PM
Astrakhan Standard Time-(UTC+04:00) Astrakhan, Ulyanovsk 5/31/2018 8:00:00 PM
Azerbaijan Standard Time-(UTC+04:00) Baku 5/31/2018 8:00:00 PM
Russia Time Zone 3-(UTC+04:00) Izhevsk, Samara 5/31/2018 8:00:00 PM
Mauritius Standard Time-(UTC+04:00) Port Louis 5/31/2018 8:00:00 PM
Saratov Standard Time-(UTC+04:00) Saratov 5/31/2018 8:00:00 PM
Georgian Standard Time-(UTC+04:00) Tbilisi 5/31/2018 8:00:00 PM
Caucasus Standard Time-(UTC+04:00) Yerevan 5/31/2018 8:00:00 PM
Afghanistan Standard Time-(UTC+04:30) Kabul 5/31/2018 8:30:00 PM
West Asia Standard Time-(UTC+05:00) Ashgabat, Tashkent 5/31/2018 9:00:00 PM
Ekaterinburg Standard Time-(UTC+05:00) Ekaterinburg 5/31/2018 9:00:00 PM
Pakistan Standard Time-(UTC+05:00) Islamabad, Karachi 5/31/2018 9:00:00 PM
India Standard Time-(UTC+05:30) Chennai, Kolkata, Mumbai, New Delhi 5/31/2018 9:30:00 PM
Sri Lanka Standard Time-(UTC+05:30) Sri Jayawardenepura 5/31/2018 9:30:00 PM
Nepal Standard Time-(UTC+05:45) Kathmandu 5/31/2018 9:45:00 PM
Central Asia Standard Time-(UTC+06:00) Astana 5/31/2018 10:00:00 PM
Bangladesh Standard Time-(UTC+06:00) Dhaka 5/31/2018 10:00:00 PM
Omsk Standard Time-(UTC+06:00) Omsk 5/31/2018 10:00:00 PM
Myanmar Standard Time-(UTC+06:30) Yangon (Rangoon) 5/31/2018 10:30:00 PM
SE Asia Standard Time-(UTC+07:00) Bangkok, Hanoi, Jakarta 5/31/2018 11:00:00 PM
Altai Standard Time-(UTC+07:00) Barnaul, Gorno-Altaysk 5/31/2018 11:00:00 PM
W. Mongolia Standard Time-(UTC+07:00) Hovd 5/31/2018 11:00:00 PM
North Asia Standard Time-(UTC+07:00) Krasnoyarsk 5/31/2018 11:00:00 PM
N. Central Asia Standard Time-(UTC+07:00) Novosibirsk 5/31/2018 11:00:00 PM
Tomsk Standard Time-(UTC+07:00) Tomsk 5/31/2018 11:00:00 PM
China Standard Time-(UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi 6/1/2018 12:00:00 AM
North Asia East Standard Time-(UTC+08:00) Irkutsk 6/1/2018 12:00:00 AM
Singapore Standard Time-(UTC+08:00) Kuala Lumpur, Singapore 6/1/2018 12:00:00 AM
W. Australia Standard Time-(UTC+08:00) Perth 6/1/2018 12:00:00 AM
Taipei Standard Time-(UTC+08:00) Taipei 6/1/2018 12:00:00 AM
Ulaanbaatar Standard Time-(UTC+08:00) Ulaanbaatar 6/1/2018 12:00:00 AM
North Korea Standard Time-(UTC+08:30) Pyongyang 6/1/2018 12:30:00 AM
Aus Central W. Standard Time-(UTC+08:45) Eucla 6/1/2018 12:45:00 AM
Transbaikal Standard Time-(UTC+09:00) Chita 6/1/2018 1:00:00 AM
Tokyo Standard Time-(UTC+09:00) Osaka, Sapporo, Tokyo 6/1/2018 1:00:00 AM
Korea Standard Time-(UTC+09:00) Seoul 6/1/2018 1:00:00 AM
Yakutsk Standard Time-(UTC+09:00) Yakutsk 6/1/2018 1:00:00 AM
Cen. Australia Standard Time-(UTC+09:30) Adelaide 6/1/2018 1:30:00 AM
AUS Central Standard Time-(UTC+09:30) Darwin 6/1/2018 1:30:00 AM
E. Australia Standard Time-(UTC+10:00) Brisbane 6/1/2018 2:00:00 AM
AUS Eastern Standard Time-(UTC+10:00) Canberra, Melbourne, Sydney 6/1/2018 2:00:00 AM
West Pacific Standard Time-(UTC+10:00) Guam, Port Moresby 6/1/2018 2:00:00 AM
Tasmania Standard Time-(UTC+10:00) Hobart 6/1/2018 2:00:00 AM
Vladivostok Standard Time-(UTC+10:00) Vladivostok 6/1/2018 2:00:00 AM
Lord Howe Standard Time-(UTC+10:30) Lord Howe Island 6/1/2018 2:30:00 AM
Bougainville Standard Time-(UTC+11:00) Bougainville Island 6/1/2018 3:00:00 AM
Russia Time Zone 10-(UTC+11:00) Chokurdakh 6/1/2018 3:00:00 AM
Magadan Standard Time-(UTC+11:00) Magadan 6/1/2018 3:00:00 AM
Norfolk Standard Time-(UTC+11:00) Norfolk Island 6/1/2018 3:00:00 AM
Sakhalin Standard Time-(UTC+11:00) Sakhalin 6/1/2018 3:00:00 AM
Central Pacific Standard Time-(UTC+11:00) Solomon Is., New Caledonia 6/1/2018 3:00:00 AM
Russia Time Zone 11-(UTC+12:00) Anadyr, Petropavlovsk-Kamchatsky 6/1/2018 4:00:00 AM
New Zealand Standard Time-(UTC+12:00) Auckland, Wellington 6/1/2018 4:00:00 AM
UTC+12-(UTC+12:00) Coordinated Universal Time+12 6/1/2018 4:00:00 AM
Fiji Standard Time-(UTC+12:00) Fiji 6/1/2018 4:00:00 AM
Kamchatka Standard Time-(UTC+12:00) Petropavlovsk-Kamchatsky - Old 6/1/2018 5:00:00 AM
Chatham Islands Standard Time-(UTC+12:45) Chatham Islands 6/1/2018 4:45:00 AM
UTC+13-(UTC+13:00) Coordinated Universal Time+13 6/1/2018 5:00:00 AM
Tonga Standard Time-(UTC+13:00) Nuku'alofa 6/1/2018 5:00:00 AM
Samoa Standard Time-(UTC+13:00) Samoa 6/1/2018 5:00:00 AM
Line Islands Standard Time-(UTC+14:00) Kiritimati Island 6/1/2018 6:00:00 AM

Webinar Registration

Even the bad guys use DNS to find their command and control servers on the Internet and this creates an important threat hunting opportunity you don’t want to neglect.

In previous webinars we’ve discussed indicators that a given domain name is malicious. There’s a lot more involved than just looking at the domain name itself to see if it looks like the product of a DGA (Domain name Generation Algorithm). How old is the domain? Who’s the registrant? Even the registrar can provide important hints. Is the zone file for the domain suspiciously skinny or does it contain the records you expect for a real domain?

In this webinar we will explore how to leverage domain name risk score analysis to surface indicators of compromise that are truly worth investigating. The goal is to cast as wide a net as possible while also automating as much as possible.

This type of threat hunting starts with automating domain name risk score analysis. Some with sufficient resources and requirements do this in-house but for most organizations it’s more appropriate to subscribe to a service that does this for you. Next, we need to feed our domain name risk analyzer with as many of the domains showing up in our network as we can. It’s also important that we identify all the sources of domain names available in your network: 

  • Web proxies
  • Next gen firewalls
  • DNS servers
  • Emails
    • Sender domains
    • URLs within body of email

You must progressively integrate these domain name sources into your risk analysis process. Except for email bodies, all of the domain name sources above can be gleaned from logs, so your log management or SIEM is usually the best place for the integration. We’ll demonstrate collecting various logs in Splunk and comparing the domain names in those logs against the Domain Risk Score technology from DomainTools. 

In this real training for free event, I will compare the different logs and other sources of domain names available in your network with regard to how to obtain the information, what format it comes in and how to integrate. Taylor Wilkes-Pierce from DomainTools will show you how they analyze a domain name to compute it's risk score. There’s a tremendous amount of information to consider – some of which requires sophisticated technology to obtain. Here’s a couple examples:

  • To assess the completeness of a domain you need to see its zone file. But zone files aren’t usually available for the public to download. DomainTools leverages something called passive DNS to build out nearly complete zone files for every domain out there.
  • Many new domains have no other indicator of maliciousness except for being new, but if you have the Internet’s entire Domain Name System dataset at hand, including history, you can tease out connections of new domains to related older domains known to be malicious.

Once your automated system identifies a “domain of interest” what do you do with it? We’ll explore that decision. Here’s some possibilities:

  • Populate a threat-hunting dashboard showing indicators of compromise
  • In terms of UEBA, you would increase the current risk score of whichever endpoints and user accounts are associated with a domain name allowing you to factor in this IOC with others to identify the entities most likely to be involved with a compromise
  • Identify the email and sender as likely phishing attack and make sure users don’t fall for related messages and block further messages

Please join me for this real training for free event!

First Name:   
Last Name:   
Work Email:  
Phone:  
Job Title:  
Organization:  
Country:    
State:  
 

Your information will be shared with the sponsor.

By clicking "Submit", you're agreeing to our Privacy Policy and consenting to be contacted by us.

 

 

Additional Resources