#551: DNS Command & Control: Detecting Malware Traffic

#551: DNS Command & Control: Detecting Malware Traffic

Big thank you to Infoblox for sponsoring this video. For more information on Infoblox have a look at their website: https://www.infoblox.com/ // Get Wireshark Certified // Check out the official training course 📘 GET TRAINING: https://courses.davidbombal.com/l/pdp... Use code "WiresharkHack" to get a $50 discount 🔗 Learn more: https://wireshark.org/certifications In this deep dive, David Bombal is joined by Wireshark expert Chris Greer to strip down the most critical protocol on the internet: DNS. We move beyond the theory to show you exactly what DNS looks like "on the wire." Chris reveals why a staggering 92% of malware uses DNS for Command and Control (C2) and how you can use packet analysis to detect these breaches before they spread. We also debunk common myths about DNS only using UDP, explore the "Librarian" analogy for Root Servers, and walk through a live capture of a request to a real website. What You Will Learn: •Malware Detection: Why 92% of malware relies on DNS and how to spot C2 traffic. • Packet Anatomy: A line-by-line breakdown of DNS headers, Transaction IDs, and Flags in Wireshark. • The TCP Myth: Why blocking TCP port 53 on your firewall can break yournetwork (and why DNS needs it). • Troubleshooting: How to measure DNS latency (response time) to pinpoint slow network performance. • Recursive Lookups: Understanding the chain from your PC to the Root Servers and back. // Chris Greer’s SOCIAL // YouTube: / chrisgreer Official WCA training: https://courses.davidbombal.com/l/pdp... Use code "WiresharkHack" to get a $50 discount LinkedIn: / cgreer Website: https://packetpioneer.com/ // Download Wireshark pcaps from here // https://github.com/packetpioneer/yout... https://github.com/packetpioneer/yout... https://www.wireshark.org/certificati... https://packetschool.teachable.com/ // WCA Course REFERENCE// Official WCA training: https://courses.davidbombal.com/l/pdp... Use code "WiresharkHack" to get a $50 discount // Chris’ DNS Series on YouTube ‘’ • Your First DNS Lookup—Captured and Explained // Link to YouTube VIDEO: • Video // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 0:52 - More Wireshark! // It's always DNS 02:45 - Infoblox sponsored segment 03:37 - DNS basics in Wireshark // How DNS works 06:52 - Analysing the DNS packet capture 08:32 - Destination address explained 10:09 - Transaction ID explained 11:13 - Flags explained 13:26 - Questions, Answer RRs & Additional RRs explained 15:39 - Additional records explained 17:07 - Response walkthrough 19:24 - Real DNS packet capture walkthrough 21:17 - Quick Wireshark tip 22:32 - Walkthrough continued 25:55 - Going deeper // How DNS resolver works 32:41 - More on Chris Greer YouTube channel and more to come 35:36 - Conclusion Please note that links listed may be affiliate links and provide me with a small percentage /kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #dns #infoblox #wireshark

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(500)

#577: My Dream "home lab"

#577: My Dream "home lab"

Join me for an exclusive, behind-the-scenes tour of Cisco's purpose-built $20 million AI data center lab in San Jose. AI is revolutionizing the tech industry, but running massive 10,000 GPU clusters c...

22 Maj 28min

#576: How to track dark ships using OSINT (with demos)

#576: How to track dark ships using OSINT (with demos)

Big thank you to DeleteMe for sponsoring this video. Use my link https://joindeleteme.com/Bombal to receive a 20% discount or use the QR Code in the video. In this OSINT deep dive, professional OSINT...

23 Apr 49min

#575: AI attackers are winning. Here is the SECRET to survive.

#575: AI attackers are winning. Here is the SECRET to survive.

Are AI attackers winning the cybersecurity war? In this video, I sit down with Daniel Miessler, a 25-year security veteran, to discuss the terrifying reality of AI-driven cyber attacks and the massive...

14 Apr 1h

#574: Hacking Windows Active Directory in 10 minutes

#574: Hacking Windows Active Directory in 10 minutes

Thank you ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/david...

14 Apr 25min

#573: WhatsApp Hackers for Hire on the Dark Web (Surprisingly cheap)

#573: WhatsApp Hackers for Hire on the Dark Web (Surprisingly cheap)

Thank you to ThreatLocker for sponsoring my trip to ZTW26 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/d...

7 Apr 27min

#572: How Cisco Protects AI Agents in Modern Data Centers

#572: How Cisco Protects AI Agents in Modern Data Centers

Big thanks to Cisco for sponsoring this video and sponsoring my trip to Cisco Live Amsterdam 2026. Join David as he sits down with Cisco's Dave West (SVP, Global Specialists), to unpack the technical...

31 Mars 14min

#571: Google Big Sleep: The End of Human Hackers?

#571: Google Big Sleep: The End of Human Hackers?

Big thank you to DeleteMe for sponsoring this video. Use my link http://jointdeleteme.com/Bombal to receive a 20% discount or use the QR code in the video. Welcome back to the channel! In this deep ...

31 Mars 1h 8min

#570: 100 Terabit Smart Switches: What You Need to Know

#570: 100 Terabit Smart Switches: What You Need to Know

Thank you to Cisco for sponsoring my trip to the Cisco AI Lab in San Jose. In this deep dive into the future of data center networking, we sit down to explore the massive shifts happening in AI infra...

31 Mars 36min

Populärt inom Teknik

uppgang-och-fall
market-makers
elbilsveckan
rss-elektrikerpodden
rss-laddstationen-med-elbilen-i-sverige
developers-mer-an-bara-kod
bli-saker-podden
rss-technokratin
bilar-med-sladd
rss-veckans-ai
natets-morka-sida
skogsforum-podcast
hej-bruksbil
bosse-bildoktorn-och-hasse-p
rss-uppgang-och-fall
rss-it-sakerhetspodden
rss-powerboat-sverige-podcast
rss-snacka-om-ai
ai-sweden-podcast
rss-en-ai-till-kaffet