Threat Hunting Malware Communication over DNS episode artwork

EPISODE · Jan 17, 2026 · 1H 26M

Threat Hunting Malware Communication over DNS

from Antisyphon Training Anticasts · host Antisyphon Training

Are attackers hiding in your DNS traffic right now?🔗 Register for FREE Infosec Webcasts, Anti-casts & Summits – https://poweredbybhis.comJoin instructor Faan Rossouw for a free one-hour training on hunting malware that uses DNS as a covert communication channel.C2 frameworks, RATs, and backdoors frequently exploit DNS to stay hidden - sometimes for months. High-profile attacks like SolarWinds' Sunburst demonstrate just how devastating undetected DNS exfiltration can be.This Antisyphon Anti-Cast focuses on behavior-based threat hunting techniques that go beyond signatures to uncover suspicious DNS activity attackers think they've hidden.You'll learn how to:* Recognize network artifacts that DNS tunneling produces* Identify anomalies in DNS record types that signal malicious use* Leverage open-source tools like Zeek, RITA, and Sysmon to detect malware abusing DNS* Build detection strategies that make it very hard for DNS-based threats to remain hiddenIf you're ready to stop trusting DNS and start verifying it, this session will give you the practical skills to hunt what's lurking in your network.Chapters:(00:00) - Intro - Threat Hunting Malware Communication over DNS (00:42) - Introducing Faan (02:17) - Threat Hunting C2 Over DNS (03:49) - Threat Hunting - What is it and why is it awesome? (05:31) - Assumed Compromise (06:44) - David J. Bianco – Pyramid of Pain Guy (13:17) - C2 Over DNS (27:52) - TXT Record Abuse (32:35) - Null Record (34:56) - CNAME, MX, SRV… Oh my (38:15) - DNS Sandwhich (42:37) - ID Field Missuse (48:47) - EDNS0 (52:22) - Encrypted DNS (55:04) - Main Takeaway (56:03) - The Workshop: Build a Reflective Shellcode Loader C2 in Golang (57:40) - Q&A Start (01:00:04) - DNS and Splunk? (01:01:37) - Suggestions for Detecting DGA? (01:03:14) - Offensive Security Tooling from a Threat Hunter Perspective (01:07:16) - Restrict outbound DNS to protect against C2? (01:08:55) - Communicating the value of Threat Hunting to Higher Ups. (01:13:38) - Closing Remarks Creators & Guests Faan Rossouw - Guest Zach Hill - Host Meagan Bentley - Producer Brought to you by:Black Hills Information Security https://www.blackhillsinfosec.comAntisyphon Traininghttps://www.antisyphontraining.com/Active Countermeasureshttps://www.activecountermeasures.comWild West Hackin Festhttps://wildwesthackinfest.comClick here to view the episode transcript.

Episode metadata supplied by the publisher feed · Published Jan 17, 2026

Embed this episode

NOW PLAYING

Threat Hunting Malware Communication over DNS

0:00 1:26:09

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Antisyphon Training Anticasts?

This episode is 1 hour and 26 minutes long.

When was this Antisyphon Training Anticasts episode published?

This episode was published on January 17, 2026.

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Antisyphon Training Anticasts episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!