- Posted on
- Featured Image
Hands-on guide to detecting DNS threats from the command line using tcpdump+tshark, Bash/awk feature engineering (qname length, label count, digit ratio, entropy), and a Python Isolation Forest for unsupervised anomaly detection. Includes rotating PCAP capture, CSV parsing, syslog/JSON alerts, cron automation, tuning tips, and examples catching tunneling, DGAs (NXDOMAIN storms), and misconfigurations.