WHOIS Your Daddy: Tracking Iranian-backed Cyber Operations with Passive DNS
Security BSides San Francisco via YouTube
Finance Certifications Goldman Sachs & Amazon Teams Trust
Live Online Classes in Design, Coding & AI — Small Classes, Free Retakes
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore how passive DNS data can uncover sophisticated Iranian-backed cyber operations through domain infrastructure analysis in this 21-minute conference talk. Discover how a single unique name server connected to Iran-nexus cyber activity reveals an extensive network of malicious name servers with potential nation-state connections. Learn the methodologies for tracking cyber threat actors by examining how one typosquatting domain can be traced through passive DNS analysis to expose multiple name servers actively used for malware distribution. Gain insights into the interconnected nature of threat actor infrastructure and understand how domain registration patterns and DNS relationships can reveal the scope and scale of state-sponsored cyber campaigns targeting various organizations and sectors.
Syllabus
BSidesSF 2025 - WHOIS Your Daddy: Tracking Iranian-backed Cyber Operations...(Austin Northcutt)
Taught by
Security BSides San Francisco