DNS

  1. Repurposing 32-bit Laptop as Linux Firewall for Cybersecurity Lab - Configured dnsmasq as a local DNS resolver and implemented domain blocking to act as a DNS sinkhole.
  2. Developing Wazuh Decoders and Rules for Lab Firewall - Analyzed Layer 7 DNS telemetry to build detection rules for anomalous behavior, such as high frequencies of NXDOMAIN responses (DGA activity) and the abuse of TXT/NULL records for DNS tunneling.