Course

DNS Investigations: Resolution, Telemetry, and Threat Decisions

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Intermediate
Modules 3
Lessons 6
Time 5 hr 5 min
Language en
Created by Threat Intelligence Lab
Updated 11 September 2026
DNS InvestigationsClient identity, recursive resolution, record context, time, and corroborating telemetry turn queries into defensible decisions.PRACTICAL SECURITY OPERATIONSDNS InvestigationsClientResolverRecordsCorroborationResolutionEVIDENCE → REASONING → DEFENSIBLE ACTION

About this course

DNS data appears in phishing, malware, endpoint, cloud, and network investigations, yet it is easy to overread. This course gives SOC analysts, threat hunters, and network defenders a working model of stub resolvers, recursive resolvers, authoritative servers, resource records, TTLs, negative caching, encrypted transports, and enterprise logging. Learners examine suspicious domains and query patterns without treating lexical oddity, NXDOMAIN volume, or a reputation result as proof. They correlate client, resolver, DHCP, endpoint, proxy, and identity evidence; test tunneling and beaconing hypotheses; and document bounded conclusions. Completion means the learner can reconstruct what a DNS record proves, identify the client and collection boundary, scope related activity, and recommend precise blocking or follow-up with stated confidence.

What you'll learn

  • ✓ Trace a DNS answer through client, recursive, cache, delegation, and authoritative roles.
  • ✓ Interpret common record types, TTLs, NXDOMAIN, NODATA, and resolution failures without inventing chronology.
  • ✓ Assess resolver and endpoint telemetry while accounting for identity, encrypted DNS, caching, and retention gaps.
  • ✓ Test suspicious-domain, tunneling, and beaconing hypotheses and produce precise response recommendations.

Before you begin

You will get more from this course if these foundations are already familiar.

  • Basic IP networking and log analysis — Learners should understand IP addresses, client-server communication, timestamps, and the purpose of logs. Prior DNS administration or packet-capture expertise is not required.

Course content