![Hands-On Network Forensics](https://wfqqreader-1252317822.image.myqcloud.com/cover/754/36698754/b_36698754.jpg)
上QQ阅读APP看书,第一时间看更新
DNS servers logs
Name server query logs can help understand IP-to-hostname resolution at specific times. Consider a scenario where, as soon as a system got infected with malware on the network, it tried to connect back to a certain domain for command and control. Let's see an example as follows:
![](https://epubservercos.yuewen.com/3901CA/19470380401498806/epubprivate/OEBPS/Images/99c4eaf9-a092-4eb1-8116-65d4bdb0d5cc.png?sign=1739286275-UyBwn0sCyojXNkeTw5u4aAH2bRn72CV6-0-742ce0f58c8fcdfaad7a1da6fb6f7b8f)
We can see in the preceding screenshot that a DNS request was resolved for malwaresamples.com website and the resolved IP address was returned.
Having access to the DNS query packets can reveal Indicators of Compromise for a particular malware on the network while quickly revealing the IP address of the system making the query, and can be dealt with ease.