Just hacker things
  • Analyst Tip: Suspicious DNS Behavior

    2016-06-09

    The following rules of thumb may be used to build analytics to search for suspicious DNS-related activity. I have provided references that support their use wherever possible. Reference Sudden short, large burst of queries for a domain Domain resolves to multiple IPs in different ASes, countries, and/or regions (A RRs) TTL changes over period of time Reference IP assigned to domain changes frequenty over a period of time Reference…more

    HowToAnalyst TipsHuntBlue Team

  • Converting pcap files to network flow data

    2015-10-05

    Pcap data is a wonderful resource; indispensible when doing certain kinds of analyses. Sometimes, however, you want to be able to use network flow data instead. Flow is much more compact, and allows you to more easily explore the relationships among hosts on a network before digging into the nuts and bolts with pcap. It also allows you to archive months or years of data in a much more efficient manner than you can with pcap.…more

    HowToPcapNetflowSiLK

  • «
  • 11

Just hacker things

Powered by Hugo and the Notepadium