Tech Library is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them. Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


SUNBURST: Mapping Malicious Activity Using Farsight Historical Passive DNS

Aug 10, 2020

By studying the investigation into the SUNBURST attack, this case study demonstrates how cyber analysts can easily and quickly examine and visualize the scale of a malware attack— whether during or after the incident—using Farsight DNSDB passive DNS data and Maltego. It also takes a close look at the attack pattern of SUNBURST and provides insights into the malware's behavior.


Farsight Security