1 LogSource to rule them all: What DNS Is Telling You(That You're Not Listening)

No ratings

Presented at BSides Joburg 2026 by

Every organisation on this continent is generating DNS logs right now. Very few of them are reading those logs for threats. That single oversight is letting attackers use the most trusted protocol on your network as a covert highway for command and control, data exfiltration, and long-term persistence. South Africa now faces nearly 2,000 cyberattacks per organisation per week, yet most SOCs are drowning in endpoint alerts while DNS queries whisper attacker activity in plain text, completely unread. This talk shows what a single, generally available log source reveals: C2 beaconing hidden in query frequency, data leaving your network one subdomain at a time, and malware phoning home through resolvers you trust.