#551: DNS Command & Control: Detecting Malware Traffic episode artwork

EPISODE · Feb 23, 2026 · 36 MIN

#551: DNS Command & Control: Detecting Malware Traffic

from David Bombal · host David Bombal

Big thank you to Infoblox for sponsoring this video. For more information on Infoblox have a look at their website: www.infoblox.com/// Get Wireshark Certified //Check out the official training course📘 GET TRAINING:courses.davidbombal.com/l/pdp...Use code "WiresharkHack" to get a $50 discount🔗 Learn more: wireshark.org/certificationsIn this deep dive, David Bombal is joined by Wireshark expert Chris Greer tostrip down the most critical protocol on the internet: DNS. We move beyond thetheory to show you exactly what DNS looks like "on the wire." Chris reveals why a staggering 92% of malware uses DNS for Command and Control (C2) and how you can use packet analysis to detect these breaches before they spread. We also debunk common myths about DNS only using UDP, explore the "Librarian" analogy for Root Servers, and walk through a live capture of a request to a real website.What You Will Learn:•Malware Detection: Why 92% of malware relies on DNS and how to spot C2 traffic.• Packet Anatomy: A line-by-line breakdown of DNS headers, Transaction IDs, and Flags in Wireshark.• The TCP Myth: Why blocking TCP port 53 on your firewall can break yournetwork (and why DNS needs it).• Troubleshooting: How to measure DNS latency (response time) to pinpointslow network performance.• Recursive Lookups: Understanding the chain from your PC to the Root Servers and back.// Chris Greer’s SOCIAL //YouTube: / chrisgreerOfficial WCA training: courses.davidbombal.com/l/pdp...Use code "WiresharkHack" to get a $50 discountLinkedIn: / cgreerWebsite: packetpioneer.com/// Download Wireshark pcaps from here //github.com/packetpioneer/yout...github.com/packetpioneer/yout...www.wireshark.org/certificati...packetschool.teachable.com/// WCA Course REFERENCE//Official WCA training: courses.davidbombal.com/l/pdp...Use code "WiresharkHack" to get a $50 discount// Chris’ DNS Series on YouTube ‘’• Your First DNS Lookup—Captured and Explained// Link to YouTube VIDEO:• Video// David's SOCIAL //Discord: discord.com/invite/usKSyzbTwitter: www.twitter.com/davidbombalInstagram: www.instagram.com/davidbombalLinkedIn: www.linkedin.com/in/davidbombalFacebook: www.facebook.com/davidbombal.coTikTok: tiktok.com/@davidbombalYouTube: / @davidbombalSpotify: open.spotify.com/show/3f6k6gE...SoundCloud: / davidbombalApple Podcast: podcasts.apple.com/us/podcast...// MY STUFF //www.amazon.com/shop/davidbombal// SPONSORS //Interested in sponsoring my videos? Reach out to my team here: [email protected] note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!Disclaimer: This video is for educational purposes only.#dns #infoblox #wireshark

Episode metadata supplied by the publisher feed · Published Feb 23, 2026

Embed this episode

NOW PLAYING

#551: DNS Command & Control: Detecting Malware Traffic

0:00 36:33

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of David Bombal?

This episode is 36 minutes long.

When was this David Bombal episode published?

This episode was published on February 23, 2026.

Can I download this David Bombal episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!