WHOIS Your Daddy: Tracking Iranian-backed Cyber Operations with Passive DNS
Security BSides San Francisco via YouTube
Live Online Classes in Design, Coding & AI — Small Classes, Free Retakes
The Most Addictive Python and SQL Courses
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
Explore how passive DNS data can uncover sophisticated Iranian-backed cyber operations through domain infrastructure analysis in this 21-minute conference talk. Discover how a single unique name server connected to Iran-nexus cyber activity reveals an extensive network of malicious name servers with potential nation-state connections. Learn the methodologies for tracking cyber threat actors by examining how one typosquatting domain can be traced through passive DNS analysis to expose multiple name servers actively used for malware distribution. Gain insights into the interconnected nature of threat actor infrastructure and understand how domain registration patterns and DNS relationships can reveal the scope and scale of state-sponsored cyber campaigns targeting various organizations and sectors.
Syllabus
BSidesSF 2025 - WHOIS Your Daddy: Tracking Iranian-backed Cyber Operations...(Austin Northcutt)
Taught by
Security BSides San Francisco