Domain Name Investigation under cyber forensic

SaurabhShukla228405 4 views 27 slides Oct 22, 2025
Slide 1
Slide 1 of 27
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27

About This Presentation

This document explains the Domain Name Investigation in Cyber forensics.


Slide Content

Introduction to Domain Name
Inlaymanlanguagethewebsiteisalsoknownas
domainname.Incyberworldsomedomainnamemay
berelatedtocybercrime.Thisdomainnameprovides
ahugeamountofinformationrelatedtocyber
criminals.criminals.
DNSstandsforDomainNameSystem.Itresolvesthe
websitenametoitscorrespondingIPaddress.Inother
words,theobjectiveofDNSistoresolvethefully
qualifieddomainname(FQDN)intoanIPaddress.
Thisprocessisknownasnameresolution.

DNS Zones
TheDNShastwozones,thefirstzoneisknownas
forwardlookupzoneandthesecondisknownasthe
reverselookupzone.
ForwardLookupzone------DomaintoIPaddress
ReverseLookupzone-------IPtoDomainname
DNSperformsthequeryusingtheDNSdatabase.The
databasecontainsIPaddress,Hostname,MXrecord,
etc.ThestructureoftheDNSdatabaseisdistributed,
replicated,andhierarchicalinnature

DNS Database

DNS Database

CNAME Record

CNAME Record map one domain name to another
domain name

A Record

MX Record

SOA Record

SOA record is also known as Start of Authority Record.
It basically contains master and slave DNS record for
sync purpose only.

Time to live (TTL)

Timetolive(TTL)iswhatdictateshowlongyourrecords
staycached.Forexample,forhowlongyourArecordwill
becachedbeforetheretrievalofanewcopyofthe
recordfromDNSservers.Therecordstorageisknownas
theDNSCache,andtheactofstoringrecordsiscalled
cachingcaching

Time to live (TTL)

Theunitsusedareseconds.AnoldercommonTTLvalueforDNSwas
86400seconds,whichis24hours.ATTLvalueof86400wouldmeanthat,
ifaDNSrecordwaschangedontheauthoritativenameserver,DNSservers
aroundtheworldcouldstillbeshowingtheoldvaluefromtheircachefor
upto24hoursafterthechange.

Nameserver

ADNSresolverisapieceofsoftwarethatinitiatesDNSquerieswhenever
youtrytoaccessawebsiteorinternetresourcebydomainname.The
resolvercontactsnameserversandasks“WhatistheIPaddressforthis
domainname?”

ThenameserveristhededicatedservercomputerthathastheDNSrecords
storedandwhichlooksuptherightIPaddresstosendbacktotheresolver.

Authoritative server

AnAuthoritativeserverprovidesdefinitiveanswersto
DNSqueries,suchasmailserverIPaddressorwebsite
IPaddress(Aresourcerecord).Itdoesnotsimply
returncachedresponsesfromanothernameserver,
butratherprovidesanswerstoqueriesaboutdomain
namesthatareconfiguredinitssystem.namesthatareconfiguredinitssystem.
Note:-“Authoritativenameserver"and"nameserver"
arenotthesame.Whileallauthoritativeserversare
nameservers,notallnameserversare
authoritative;somenameserversarerecursive
resolvers,whicharenotauthoritative.

Commands

How DNS works in details

SupposeanorganizationABCismanagedbythreedepartmentsHR,
Accounts,andIT.

Theownermonitorstheperformanceoftheorganization.Thedepartments
HR,accounts,andIThave5memberseach.

Supposeanyonewantstocontactamemberofanydepartment.The
questionariseswherehe/sheshouldcontactfirst.

Hence,youhavetochecksalistofnamesalongwithphonenumbers.WeHence,youhavetochecksalistofnamesalongwithphonenumbers.We
knowthateachdepartmenthasaheadofdepartment(HoD)tohandlea
queryofspecificdepartment.
HoDName Department
Anju HR
Rajesh ACCOUNTS
Vishal I.T

How DNS works
The members of I.T departments are Mr. Vishalis HoDof I.T department
Members Department
Tom
I.T
Jhon
RameshRamesh

How DNS works

The list of members in the HR department are
Members Department
Rudransh
HR
Ivan
Jyoti

How DNS works

The list of members in the ACCOUNTSdepartment
Members Department
Shail
ACCOUNTS
NeerajKumar
KPSingh

How DNS works

SupposeifanyonewantstocontactMr.Tomworkinginthe
I.T.department,thenhe/shemustfirstcontacttheHoDof
I.T.,thatis,Mr.Vishal,andthenhe/shecancontactthat
particularmember,thatis,TomofI.T.Now,youcan
comparethissituationtoDomainNameandIPaddress.

HereMr.Vishalworksasanameserverandphonenumber

HereMr.Vishalworksasanameserverandphonenumber
equaltoIPaddressrelatedtoaspecificdepartment.You
canassumethedepartmentnameasDomainName
andMr.TomworksasaWebserver.Inthesameway,all
membersofdepartmentsworkasawebserverandHoD
worksasnameservers.Thelistsareworksaszonesfile.

DOMAIN NAME INVESTIGATION USING OSINT
Thefirststepinyourinvestigationistovisitthewebpagesofyourtargetcompany.
Thereisalotofimportantinformationthatcanbeobtainedfromatarget's
website.Theyincludebutarenotlimitedtothefollowing.

Physical address

Branch office locations

Key employees

Current job postings (This may reveal technologies used in the company)

Phone numbers

Partner companies

Open hours and holidays

News about target organization (merger or acquisition news)

Technologies used in building the website

Email system used

IT technologies (hardware and software) used by target organization

VPN provider (if any)

Digital files and metadata

Information about the organization’s employees

DOMAIN NAME INVESTIGATION USING OSINT
Thenextstepistodetermineandrecordthedomainname
registrationinformation.Thefollowingonlineresources
canbeusedtoobtainregistrationinformation:

www.network-tools.com

www.samspade.org

www.geektools.com

www.geektools.com

www.apnic.net(Asia)

www.checkdomain.com

www.lacnic.net

www.ripe.net(Europe)

www.whois.comwww.dnsstuff.com

Domain name registration information
The typical information provided includes—
■Registered owner’s name and address.
■Billing information.
■Administrative contact.
■Range of IP addresses associated with the domain.
Technical contact information. ■Technical contact information.

Where’s the evidence?
Information can be found in numerous locations,
including—

User’s computer.

ISP for the user.

ISP for a victim and/or suspect.
Log files contained on the victim’s and/or suspect’s—

Routers.

Firewalls.

Web servers.

E-mail servers.

Other connected devices.

Information that may be obtained from the ISP includes

Subscriberinformationsuchastheregisteredowner,
address,andpaymentmethod.

Transactionalinformationsuchasconnectiontimes,
dates,andIPaddressused.
Note:-SomeISPsmaskedtherealinformationof
subscriberstorandominformation.Inthiscaseyousubscriberstorandominformation.Inthiscaseyou
havetocontacttheISPsviae-mail.Exampleisgivenin
nextslide

User information

Thank you
Tags