paloaltonetworks:dns_security
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| paloaltonetworks:dns_security [2023/05/26 05:29] – [DNS Techniques] bstafford | paloaltonetworks:dns_security [2025/08/29 13:27] (current) – [Details] bstafford | ||
|---|---|---|---|
| Line 7: | Line 7: | ||
| [[https:// | [[https:// | ||
| + | ===== DoT/DoH ===== | ||
| + | PAN-OS 11.2.1 [[https:// | ||
| + | |||
| =====Data Sources===== | =====Data Sources===== | ||
| Line 24: | Line 27: | ||
| * Stops newly registered domains 6x faster than publicaly avaialble scanners | * Stops newly registered domains 6x faster than publicaly avaialble scanners | ||
| + | New in mid 2025 | ||
| + | * Detection of unknown C2 threats developed using the open source Sliver C2 framework (ATP) | ||
| + | * Enhanced Empire C2 deteciton | ||
| + | * Protection against DNS relaying attacks, also known as Data Exfiltration via HTTP request headers (ATP+ADNS) | ||
| + | * Domain Masquerading Detection, Malicious TDS Detection (ADNS) | ||
| + | * AI Categorization, | ||
| + | * Endpoint DLP | ||
| =====URL Categories Blockable===== | =====URL Categories Blockable===== | ||
| Line 39: | Line 49: | ||
| ===== DNS Techniques ===== | ===== DNS Techniques ===== | ||
| * Dangling DNS (PAN only) | * Dangling DNS (PAN only) | ||
| + | * WildCard DNS (PAN only) | ||
| + | * NXNS Attack (PAN only) | ||
| + | * CNAME Cloaking | ||
| + | * Ultra-Slow DNS Tunneling | ||
| * Data Theft | * Data Theft | ||
| * DNS Tunneling | * DNS Tunneling | ||
| Line 44: | Line 58: | ||
| * Compromised DNS Zone | * Compromised DNS Zone | ||
| * DNS Rebinding | * DNS Rebinding | ||
| - | * WildCard DNS (PAN only) | ||
| - | * NXNS Attack (PAN only) | ||
| - | * CNAME Cloaking (PAN only) | ||
| * Strategically Aged Domains | * Strategically Aged Domains | ||
| * Domain Squating | * Domain Squating | ||
| Line 54: | Line 65: | ||
| * DNS Rebinding Attacks | * DNS Rebinding Attacks | ||
| * Dangling SNA Attacks | * Dangling SNA Attacks | ||
| - | * Dictionary DGA | ||
| - | * Ultra-Slow DNS Tunneling | ||
paloaltonetworks/dns_security.1685078984.txt.gz · Last modified: by bstafford
