A SOC analyst notices a workstation repeatedly querying short, random-looking domains whose lookups often return NXDOMAIN before occasionally resolving. You need to confirm whether the activity is consistent with DGA-based command and control before containment. Which telemetry source should you query first?
Select an answer to reveal the explanation.
Short Explanation
Think of DGA hunting like listening to a kid make up fake phone numbers: the phone book tells you what was dialed, not who picked up. DNS logs show the weird, high-entropy names being looked up, so you start there before chasing process or flow noise. Don't let the fancy endpoint details distract you from the actual name resolution trail.
Full Explanation
Domain generation algorithm malware often attempts many machine-created domain names to locate a command-and-control server. DNS resolver logs are the best first source because they record the actual queried names, NXDOMAIN responses, query frequency, and timing patterns. You can search for high-entropy labels, short random-looking domains, repeated failed lookups, and clustered query bursts from one host to confirm the DGA pattern before containment. Process creation events can show a suspicious parent-child chain, but they do not directly prove the endpoint requested algorithmically generated domains unless network telemetry is joined. NetFlow records can reveal destination IPs, ports, and byte counts, but they lack the original domain names and may be misleading after name resolution or when malware rotates IPs. Proxy logs may show URLs and user-agent strings when traffic is proxied, yet they miss direct DNS lookups and non-HTTP C2 channels, so they cannot reliably establish the domain-generation behavior. Exam caveat: choose the telemetry that contains the artifact named in the question, not the source that merely correlates with it. Operational check: pivot from the endpoint to DNS resolver logs and filter for high-entropy query names and NXDOMAIN spikes tied to the host.