Following Threat Actors Rhythm to Give Them More Blues
Malachi Walker (Security Adviser · Domain Tools)
Blacks in Cyber Village @ DEF CON 33 · Day 1 · Blacks in Cyber Village
Overview
In his engaging talk, "Following Threat Actors Rhythm to Give Them More Blues," Malachi Walker, a Security Adviser at DomainTools, introduced a novel approach to cybersecurity investigations: domain intelligence analysis. This methodology leverages the inherent patterns in how threat actors establish and utilize online infrastructure, particularly within the Domain Name System (DNS), to provide early warning signs and actionable intelligence. Walker's presentation emphasized that by understanding these rhythms, defenders can proactively identify and disrupt malicious campaigns, turning the tables on adversaries who often believe they only need to be right once.

Key moments
- 0:00 Introduction to speaker and 'Domain Intelligence Analysis' approach
- 0:40 Announcing interactive DNS scavenger hunt with AirPod Pro prize
- 2:00 Overview of the talk agenda, including the scavenger hunt
- 2:45 Essential tools and decoders for the DNS scavenger hunt
- 4:00 Launching the DNS scavenger hunt with the starting domain
- 4:50 Detailed explanation of the first step and clue in the hunt
- 6:45 Advice on decoding strings and using LLMs during the hunt
Following Threat Actors Rhythm to Give Them More Blues
Speakers: Malachi Walker, Security Adviser, Domain Tools
Conference: Blacks in Cyber Village
YouTube: https://www.youtube.com/watch?v=F_BTn1FjbHU
Overview
In his engaging talk, "Following Threat Actors Rhythm to Give Them More Blues," Malachi Walker, a Security Adviser at DomainTools, introduced a novel approach to cybersecurity investigations: domain intelligence analysis. This methodology leverages the inherent patterns in how threat actors establish and utilize online infrastructure, particularly within the Domain Name System (DNS), to provide early warning signs and actionable intelligence. Walker's presentation emphasized that by understanding these rhythms, defenders can proactively identify and disrupt malicious campaigns, turning the tables on adversaries who often believe they only need to be right once.
The talk highlighted the critical role of DNS artifacts as a starting point for investigations, regardless of where an organization is in the attack timeline. Walker demonstrated how even without specialized tools, an analyst can uncover significant connections and context by meticulously examining DNS records. This approach is not merely reactive but empowers incident responders and threat hunters to anticipate future attacks and address entire malicious campaigns rather than just individual incidents, ultimately giving "more bad days to bad actors."
Background
▶ Watch: Introduction to speaker and 'Domain Intelligence Analysis' approach (0:00)
The digital landscape is a constant battleground, with threat actors continuously registering and abusing internet infrastructure to carry out their malicious objectives. From phishing campaigns and command-and-control (C2) servers to reconnaissance and data exfiltration, domains and their associated DNS records are fundamental components of almost every cyberattack. Despite their pervasive use by adversaries, the underlying patterns and artifacts left behind in the DNS often go underutilized by defenders. This creates a significant blind spot, as organizations frequently focus on endpoint detection or network traffic, overlooking the foundational intelligence available in DNS.
Traditional incident response often involves a reactive "whack-a-mole" approach, addressing individual indicators of compromise (IOCs) as they emerge. However, threat actors, whether sophisticated state-sponsored groups or novice cybercriminals, tend to reuse infrastructure, leverage similar registration patterns, or even share credentials and resources. This commonality creates a discernible "rhythm" or fingerprint in their operations. Walker underscored that recognizing these patterns is paramount, allowing defenders to move beyond isolated incident handling to a more holistic, proactive threat hunting mindset. The problem, therefore, is not a lack of data, but often a lack of awareness and a structured methodology to extract intelligence from readily available DNS information.
Key Findings
▶ Watch: Overview of the talk agenda, including the scavenger hunt (2:00)
The central finding of Malachi Walker's talk is the efficacy of domain intelligence analysis as a powerful, often overlooked, method for proactive cybersecurity. He posited that DNS artifacts serve as crucial early warning signs and connectors, enabling defenders to link seemingly disparate malicious activities and gain a comprehensive view of threat actor operations. The core insight is that threat actors, despite their attempts at stealth, inevitably leave behind patterns in their infrastructure setup and usage.
Walker highlighted several key aspects:
- DNS as the First Sign of Trouble: DNS records often provide the initial indication of malicious intent. The act of registering a domain, associating it with an IP address, and configuring various records (TXT, MX, CNAME) creates a digital footprint that, when analyzed correctly, can reveal the adversary's rhythm.
- Convergence of High-Risk Attributes: DomainTools' investigations team, as mentioned by Walker, focuses on identifying the convergence of high-risk attributes across registrars, Internet Service Providers (ISPs), and nameservers. This analysis helps uncover clusters of malicious infrastructure, moving beyond individual domains to identify broader campaigns. Their 2024 DomainTools Investigations Threat Report delves deeper into these findings, suggesting that malicious domain registration is not random but follows predictable, exploitable patterns.
- Domains Across MITRE ATT&CK: Walker pointed out that domains are not just for obvious stages like reconnaissance or phishing. They are integral to almost every stage of the MITRE ATT&CK framework, including crucial phases like Command and Control (C2). This broad utility means DNS analysis can provide insights across the entire attack lifecycle.
- Connecting the Unseen: A critical finding is the ability of domain intelligence to connect a known malicious domain (what you are seeing) to related, yet unseen, infrastructure. This allows defenders to identify and neutralize entire networks of malicious domains before they are fully weaponized, moving from reactive fire-fighting to proactive disruption.
- Empowering Defenders: By following these patterns, defenders can gain confidence in their investigations, prioritize their efforts more effectively, and ultimately "give them more bad days" by disrupting threat actor operations at scale.
Technical Deep Dive
▶ Watch: Essential tools and decoders for the DNS scavenger hunt (2:45)
The technical core of Walker's presentation revolved around practical DNS record analysis using command-line tools and web-based decoders, demonstrated through an interactive scavenger hunt. The methodology emphasizes starting with a suspicious domain and then systematically querying various DNS record types to uncover hidden clues, decode obfuscated data, and follow the breadcrumbs left by threat actors.
The primary command-line tools employed were dig (for Unix-like systems) and nslookup (for Windows), used to query specific DNS record types. The hunt began with the domain clue.mmyailythreat.com.
- TXT Record Analysis: The first step involved querying the TXT (Text) record for the initial domain. TXT records are often used for various purposes, including SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) authentication, but can also be abused by threat actors to store arbitrary data, hints, or even C2 instructions.
- Command example:
dig TXT myailythreat.com(Mac) ornslookup -type=text clue.mmyailythreat.com(Windows). - This query revealed a riddle: "You've got email, but where does it go? Add don't subtract. And now you'll know." This hinted at the next step and the importance of email-related records.
- MX Record Analysis: Following the riddle, the next logical step was to query the MX (Mail Exchange) record, which specifies the mail server responsible for accepting email messages on behalf of a domain. The riddle's "add don't subtract" clue suggested appending "email" to the starting domain.
- Command example:
dig MX email.clue.mmyailythreat.com. - The MX record revealed a long, seemingly random string. Walker noted that the string contained many repeated variables and a limited character set, suggesting a specific encoding.
- Decoding Obfuscated Strings: The long string from the MX record required decoding. Walker introduced tools like CyberChef (gchq.github.io/CyberChef) and IPVoid (ipvoid.com) as powerful web-based decoders. He also mentioned that Large Language Models (LLMs) like Google Gemini and ChatGPT could be used, though with a caveat for solving riddles directly. The string's characteristics (limited variables, long length) pointed towards Base16 (Hexadecimal) encoding. The string also contained periods, requiring it to be broken up for proper decoding.
- Decoding this string revealed another riddle: "To get my alter ego, add one label to the left for the next step's arbitrary lore in the record it was meant for." It also subtly revealed a domain change from
.comto.net, specificallyshadow.mmythreat.net. This shift from.comto.netis a common tactic for threat actors, creating "twin domains" to maintain resilience or confuse investigations.
- CNAME Record Analysis: The riddle's mention of "alter ego" and "arbitrary lore" in the "record it was meant for" led to querying the CNAME (Canonical Name) record. CNAME records create aliases for domains, often used to point a subdomain to another domain. The "alter ego" clue was crucial, emphasizing the switch to the
.nettwin domain.
- Command example:
dig CNAME shadow.mmythreat.net. - This query redirected to
next.clue.threatblockchain.com, indicating a pivot to a new, seemingly unrelated domain.
- DKIM Record Discovery: The subsequent step involved another TXT record query, this time for
next.clue.threatblockchain.com. This revealed a complex, Defcon-themed riddle. Solving the riddle pointed to a specific DKIM (DomainKeys Identified Mail) record associated with the domain. DKIM records are TXT records containing cryptographic keys used to verify the authenticity of email senders. Threat actors can embed messages or further clues within these records.
- The riddle's solution was
defcon_the_dark_tangent_domainkey.threatblockchain.com. - Querying this DKIM record (
dig TXT defcon_the_dark_tangent_domainkey.threatblockchain.com) revealed a message embedded in plain text:target.assumed-breach.com.
- GitHub and Base64: The
target.assumed-breach.comdomain, when queried for its TXT record, provided a GitHub URL. Visiting this URL led to a zip file, which, upon download, contained another interesting string. This string was then identified as Base64 encoded and required decoding using tools like IPVoid to reveal the final answer.
Throughout this technical journey, Walker emphasized that the skill lies not just in using the tools but in identifying what to decode and which encoding to use based on the string's characteristics. This iterative process of querying DNS, decoding, and following riddles mirrors the real-world investigation of sophisticated threat actor infrastructure, demonstrating how interconnected DNS artifacts can be.
Demo / Proof of Concept
▶ Watch: Detailed explanation of the first step and clue in the hunt (4:50)
The entire presentation served as an interactive DNS scavenger hunt, acting as a live demonstration and proof of concept for Malachi Walker's domain intelligence analysis methodology. The scavenger hunt was designed to immerse the audience in the investigative workflow, using only a command-line terminal and basic decoding tools. The objective was to follow a trail of DNS records and embedded clues to uncover a final "secret."
The demonstration unfolded through a series of steps, each building upon the previous one:
- Starting Point: Participants were given the initial domain
clue.mmyailythreat.comand instructed to usedigornslookup. - TXT Record for Initial Clue: The first query was for the TXT record of
myailythreat.com. This immediately yielded a riddle: "You've got email, but where does it go? Add don't subtract. And now you'll know." This simple step showcased how even basic DNS records can hold valuable, albeit obfuscated, information. - MX Record for Encoded String: Following the email hint, participants queried the MX record for
email.clue.mmyailythreat.com. This revealed a long string composed of a limited set of characters, hinting at Base16 (Hexadecimal) encoding. This stage demonstrated how threat actors often encode data within legitimate-looking records to evade simple detection. - Decoding and Alter Ego: Using web decoders like CyberChef or IPVoid, the hex string was broken down and decoded. The output was not only another riddle ("To get my alter ego, add one label to the left...") but also revealed a crucial pivot:
shadow.mmythreat.net. This demonstrated the concept of "twin domains" and how a single initial IOC can lead to related infrastructure on different TLDs. - CNAME for Redirection: The "alter ego" riddle led to querying the CNAME record for
shadow.mmythreat.net. This query returnednext.clue.threatblockchain.com, illustrating how CNAME records are used for redirection and can link seemingly disparate domains in a malicious chain. - Defcon Riddle in TXT: A subsequent TXT record query for
next.clue.threatblockchain.comunveiled a lengthy, Defcon-specific riddle. This highlighted how threat actors might embed contextual or proprietary information within DNS records, requiring a deeper understanding or external knowledge to decipher. - DKIM and Plaintext Message: Solving the Defcon riddle pointed to a specific DKIM record (
defcon_the_dark_tangent_domainkey.threatblockchain.com). Querying this TXT record surprisingly revealed a plaintext message:target.assumed-breach.com. This demonstrated that even cryptographic records can be leveraged to store cleartext information or further clues. - GitHub and Zip File: A TXT record query for
target.assumed-breach.comprovided a GitHub URL. Navigating to this URL led to a downloadable zip file, which contained the next piece of the puzzle – another encoded string. This step showed how DNS can lead to external resources and files, forming a multi-stage attack chain. - Final Base64 Decode: The string from the zip file was identified as Base64 encoded. Using IPVoid for decoding, the final clue was revealed: the instruction to sing "This Is How We Do It" by Montell Jordan.
The scavenger hunt effectively proved that by methodically querying different DNS record types, decoding obfuscated strings (using Base16, Base32, Base64), and following logical (or riddle-based) connections, an analyst can uncover complex, multi-stage threat actor infrastructure. It underscored Walker's point that DNS is not just a routing mechanism but a rich source of intelligence waiting to be exploited by diligent defenders.
Defensive Implications
▶ Watch: Advice on decoding strings and using LLMs during the hunt (6:45)
The insights from Malachi Walker's talk offer profound defensive implications, urging a shift from reactive incident response to proactive threat hunting using domain intelligence analysis. Organizations can significantly enhance their security posture by integrating DNS analysis into their daily operations and incident response workflows.
- Early Warning and Proactive Threat Hunting: DNS is often the "first sign of trouble." By actively monitoring and analyzing DNS registration data, changes in records, and the creation of new domains, defenders can identify malicious infrastructure before it is fully weaponized. This proactive stance allows for pre-emptive blocking and disruption, stopping campaigns before they impact users. Walker emphasized the importance of following threat actors' rhythms to anticipate their next moves.
- Enhanced Incident Response: When an incident occurs, traditional approaches might focus on a single IOC. However, by applying domain intelligence analysis, security teams can take a single suspicious domain and pivot to discover an entire network of related infrastructure. This allows for a comprehensive response, addressing all connected malicious entities at once, rather than putting out "fires one at a time." This efficiency saves valuable time and resources during critical incidents.
- Connecting the Dots (IOC Correlation): The ability to connect known malicious domains to previously unseen or dormant infrastructure is crucial. Threat actors often reuse registration details, IP addresses, nameservers, or even encoding techniques. By identifying these patterns and "high-risk attributes" (as highlighted by the DomainTools 2024 threat report), defenders can build a more complete picture of an adversary's operations, leading to more robust IOC correlation and threat intelligence.
- Leveraging Existing Tools and Skills: The scavenger hunt demonstrated that powerful analysis can be done with basic command-line tools like
digandnslookup, alongside free web-based decoders like CyberChef and IPVoid. This lowers the barrier to entry for many security teams, even those with limited access to expensive commercial tools. Walker also noted that LLMs (like Gemini or ChatGPT) can assist with decoding, though human analytical skill remains paramount for riddles and contextual understanding. - Understanding Adversary TTPs: By dissecting threat actor infrastructure patterns, defenders gain a deeper understanding of their Tactics, Techniques, and Procedures (TTPs). This includes their preferred encoding methods (e.g., Base16, Base64), their use of different DNS record types (TXT, MX, CNAME), and their strategies for creating resilient infrastructure (e.g., "twin domains" like
.comand.netvariants). This knowledge can be used to develop more targeted detection rules and defensive strategies. - Strategic Investment in Security: Walker addressed the challenge of securing resources for security initiatives by advocating for a business-centric approach. He suggested using frameworks like the FAIR model (Factor Analysis of Information Risk) or the NICE framework to quantify the financial impact of cyber risks and the return on investment (ROI) of proactive security measures. By demonstrating how DNS analysis can save time, prevent incidents, and even enable proactive bounties or brand building, security teams can make a compelling case to leadership that cybersecurity is a revenue driver, not just a cost center.
- Community Collaboration: The speaker encouraged sharing IOCs and research, noting that DomainTools publishes its findings on GitHub. This collaborative approach strengthens the collective defense against threat actors, reinforcing the idea that "working together as a community" is essential to giving adversaries "more bad days."
Key Takeaways
- DNS is a Critical Early Warning System: DNS artifacts often provide the very first signs of malicious activity, allowing for detection and disruption before attacks fully unfold.
- Threat Actors Follow Predictable Rhythms: Adversaries reuse infrastructure, employ consistent encoding methods, and follow discernible patterns in their domain registration and usage, which defenders can exploit.
- Domain Intelligence Connects the Dots: By analyzing DNS records (TXT, MX, CNAME), defenders can connect seemingly isolated IOCs to uncover entire networks of malicious infrastructure.
- Basic Tools Yield Powerful Insights: Significant threat intelligence can be derived using readily available command-line tools (
dig,nslookup) and free web-based decoders (CyberChef, IPVoid). - Proactive Hunting is Key to "Giving Them Blues": Shifting from reactive incident response to proactive threat hunting based on domain intelligence allows organizations to get ahead of adversaries and address entire campaigns.
- Quantify Security Value: Articulating the financial benefits and ROI of domain intelligence analysis, using frameworks like FAIR or NICE, can help secure necessary resources and elevate cybersecurity as a strategic asset.
About the Speaker(s)
Malachi Walker is a Security Adviser at DomainTools, a leading provider of threat intelligence solutions. With a robust background encompassing cybersecurity program development, in-depth DNS infrastructure analysis, and cybercrime investigation, Walker brings a unique and sharp lens to understanding and countering malicious online infrastructure. His expertise lies in deciphering the intricate patterns and rhythms of threat actors, enabling organizations to anticipate and mitigate cyber threats more effectively. Through his work, Malachi is committed to empowering defenders with actionable intelligence, making the internet a safer place by giving adversaries "more bad days."
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A vendor-affiliated speaker doing an elaborate DNS scavenger hunt dressed up as threat intelligence methodology. The core content — query TXT, MX, CNAME records, decode Base16/Base64, pivot on infrastructure — is foundational stuff any CTI analyst learned five years ago. The framing is engaging and the demo format is creative, but there's no novel research here, no new attack surface, no threat actor data that isn't already in a DomainTools marketing brochure.
Heather Calloway (CISO) — SOLID
Walker delivers a competent, practitioner-level introduction to DNS-based threat hunting with a clever pedagogical hook. It earns its place at Blacks in Cyber Village, but it doesn't clear the bar for governance relevance or senior operator decision-making — it's a skills talk, not a strategy talk.