Get a Pentest and security assessment of your IT network.

Cyber Security

Sysmon Getting DNS Query Logging with Querying Process Name

Microsoft has announced that a new version of Sysmon is coming out this week that will include the ability to log DNS queries performed on a monitored computer. Even better, it will also log the process that performed the query. This can allow administrators to quickly track down offending applications that may be connecting to unwanted sites or performing other unwanted behavior. This data can then be consumed by other tools in order to find executables creating suspicious traffic or connecting to malicious domains. With this new feature, we can expect updated configuration files and tools that can now utilize the data that this free tool provides.

Source: https://www.bleepingcomputer.com/news/microsoft/sysmon-getting-dns-query-logging-with-querying-process-name/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security