DNS Evidence: You Don’t Know What You’re Missing

Here is SANS DFIR webcast recording. You’ll learn some simple and effective ways to create logs of DNS traffic, what specific value they can provide for other evidence types, and how to exploit these logs at scale: