DNS Query Log
Definition
A record maintained by a DNS resolver listing each domain name query, the requesting IP address, the response, and the timestamp. DNS query logs are a primary source of evidence in investigations involving malware command-and-control, phishing, and DNS tunnelling.
- Recorded by
- DNS resolver
- Fields logged
- Domain queried, requesting IP, response, timestamp
- Common uses
- Malware C2, phishing, DNS tunnelling investigations
- Layer
- Application layer, network forensics
Common questions
Why are DNS query logs valuable when the actual malicious traffic was encrypted?+
Even when payload content is encrypted, the resolver still sees the plaintext domain name being looked up, so query logs can reveal which command-and-control or exfiltration domains a host contacted regardless of downstream encryption.
What limits the completeness of DNS query logs in an investigation?+
Retention periods vary and can be short, and a host using its own resolver, a VPN, or DNS-over-HTTPS to a third-party service can bypass the organisation's logged resolver entirely, leaving no local record of the query.
Related terms
- Encapsulation
- The process by which each OSI layer wraps the payload from the layer above it inside its own header (and sometimes trailer)....
- PCAP (Packet Capture File)
- A binary file format that stores raw network traffic captured from a network interface. Tools such as Wireshark, tcpdump, and Zeek read...
- Protocol Data Unit (PDU)
- The named unit of data at each OSI layer: a frame at Layer 2, a packet at Layer 3, a segment at...
- Server Name Indication (SNI)
- A TLS extension sent in plaintext in the Client Hello message that identifies the hostname the client intends to reach. SNI is...
- TCP Three-Way Handshake
- The connection establishment sequence in TCP: the client sends SYN, the server responds SYN-ACK, and the client completes with ACK. The timestamps...