3 Reasons to Tune in to “The Threat Hunter’s Newest Weapon: DNS Data”

This Wednesday, Chris Day, Chief Cybersecurity Officer at Cyxtera will be joining us for an exclusive webinar, “The Threat Hunter’s Newest Weapon: DNS Data”.

This Wednesday, Chris Day, Chief Cybersecurity Officer at Cyxtera will be joining us for an exclusive webinar, “The Threat Hunter’s Newest Weapon: DNS Data”.

91% of malware attacks leverage DNS. So why aren’t more organizations using this gold mine of data to battle advanced persistent internal threats? With DNS data being be one of the most severely underutilized tools in battling bad actors, Chris Day will explain how system administrators, network engineers, and all threat hunters can use DNS data as a part of their cybersecurity arsenal. As 2017 comes to a close, Day will provide some great insight into what’s happened this past year, and what we can expect in 2018. If you’re still not convinced, here are just a few reasons why you should register.

1) You need to know what to look for

As a threat hunter, this question always arises: What should you be looking for in my DNS data? Due to the sheer volume of DNS queries that get logged, it can be difficult to tell what exactly this data can tell you about cyber attacks. One of the reasons DNS data is so underutilized is that many people don’t even know where to start. Wednesday’s webinar will take you through the hints to look for in your DNS data.

2) You need to know what to do right now

There are likely internal threats lurking on your network as you’re reading this. So, what can you do about it now? It’s important to know that while you may not be leveraging your DNS data, it’s all already there, ripe for analysis. There are steps you can take in the short-term to start preparing and protecting your network. Day will give us a few recent examples of how he used DNS to better understand cyberattacks.

3) You need to know what’s next

We are living in the age of inevitability, not prevention. Cyber threats are getting smarter and smarter and acting much faster than we seem to be able to react. That being said, it’s that much more important for threat hunters to shift their strategies and understand how to harness the power of DNS not only battling external threats but internal threats. Knowing what to look for in your data and what to anticipate can give you invaluable insight as far as forensics and detection.

All of this is just glimpse of what’s to come in Wednesday’s webinar. Make sure to tune in on December 13 at 2:00 PM EST to get the full picture, complete with a Q&A with Chris Day himself. Register here!

Key Takeaways
  • DNS data is a critical yet underutilized source for detecting and analyzing cyber threats, despite being involved in 91% of malware attacks.
  • The volume and complexity of DNS query logs make it challenging for security teams to know which indicators and patterns to focus on for threat hunting.
  • Most organizations already collect DNS data that can be immediately analyzed to uncover existing internal threats without requiring new infrastructure.
  • Effective use of DNS data enables better understanding of recent cyberattacks through concrete examples and forensic insights.
  • As prevention becomes less realistic, threat hunters must shift strategies toward detection and response using DNS data for both internal and external threat visibility.
  • Knowing what to look for in DNS telemetry and how to interpret it is essential for improving threat detection, investigation, and overall cybersecurity posture.

Published in:


An avatar of the author

Anna is a passionate content writer who’s always eager to learn something new about cyber security.

Related content

Replace BIND and ISC with Micetro DNS/DHCP Server (MDDS)

Tired of patching and manually configuring BIND DNS and ISC DHCP? Discover how Micetro MDDS appliances can replace them for modern DDI.

Read more

Automate it all in Integrity with REST v2 API-first DDI management

Discover API-first DDI with Integrity X by using REST v2 to automate DNS, DHCP, and IPAM for scalable, secure network operations.

Read more

Agentic AI adoption in network observability propels NetOps teams

Network observability is crucial for today’s networks and even more capable with agentic AI, according to new Omdia and BlueCat research.

Read more

Stop the ticket bottleneck: Automate DNS, DHCP, and IPAM with Quick Service

Automated DNS, DHCP, and IPAM (DDI) service delivery enables organizations to replace manual, ticket-based workflows with policy-driven, self-service…

Read more

⏳ Cisco Live is almost here. Put BlueCat on your agenda for smarter, more secure networks.