Two can play at that game: Thinking like a malicious adversary

In this whiteboard session, learn how DNS is critical to your cybersecurity strategy and how to keep adversaries in mind when structuring your domains.

When we set out to counter cyber threats, you can draw a number of parallels from actual battles. Sun Tzu says it best in The Art of War: the most important part of any battle is not the fight, but the preparation. Because before you set off into battle, you must first know your enemy.

It’s the foundation of any combat strategy, including cyber security. Because a malicious adversary has two intentions: fool the target and avoid being blocked. You need to know how bad actors do this through DNS and how they weaponize domains. That should be the starting point of your cyber security tactics.

DNS is relevant throughout the kill chain as domains are used throughout the process, from installation to delivery to command and control. They come in to play relatively early in the process, and bad actors start by identifying the types of domains or even the domain generation algorithms they’re going to use. The better you understand how these bad actors operate, the better (and earlier) you can spot them.

With that being said, putting yourself in the mind of your adversary puts you at a great advantage, because if you don’t know what you’re fighting, how can you expect to fight it? DNS is crucial to developing a counter strategy and can be used to spot nefarious patterns or intents that may elude existing security defenses. 

Cyber security professionals can use this approach proactively, like policy-setting in DNS Edge; by anticipating your adversary’s next move, you can preemptively block certain known bad domains. They can also use it reactively, like conducting malware forensics on something malicious that’s been found.

If you’re looking at something malicious that’s already taken place, you can see what damage has been inflicted, domains the malware has reached out to, and who else on the network might have been infected. There is tons of rich DNS data that can provide invaluable insights. By combing through DNS logs, you’ll be able to see who else was communicating out to it, and pair logs with individual machines and assets.

You need to give some credit to these malicious actors, because they know your cyber defenses inside out, and are experts in cleverly navigating through your cyber walls. Never underestimate their tactics. By gaining an in-depth understanding of how, why, and when they create these bad domains, your threat hunting will be that much more effective.


Published in:


An avatar of the author

BlueCat provides core services and solutions that help our customers and their teams deliver change-ready networks. With BlueCat, organizations can build reliable, secure, and agile mission-critical networks that can support transformation initiatives such as cloud adoption and automation. BlueCat’s growing portfolio includes services and solutions for automated and unified DDI management, network security, multicloud management, and network observability and health.

Related content

Simplify Microsoft DNS, DHCP, and Active Directory with Micetro

Learn how Micetro makes it easy to administer Microsoft DNS, DHCP, and Active Directory sites and subnets and manage your DDI environment.

Read more

Get insight into your DDI environment with Live DDI Analytics

Enroll in our technology preview today to use the Live DDI Analytics tool to get real-time reports and analysis for your DDI environment.

Read more

Three business-focused reasons to embrace Unified DDI

Discover with BlueCat how cost optimization, risk reduction, and accelerated digital transformation offer three reasons to adopt Unified DDI.

Read more

Enhance RBAC for Microsoft DNS and DHCP servers with Micetro

Learn how easy it is to implement enhanced role-based access controls for Microsoft DNS and DHCP server environments with Micetro.

Read more