hunting-for-dns-based-persistence
mukul975/Anthropic-Cybersecurity-Skills
This skill provides a structured methodology for threat hunting DNS-based persistence mechanisms. It detects unauthorized changes such as DNS hijacking, dangling CNAME records enabling subdomain takeover, wildcard DNS abuse, or unauthorized NS delegation modifications. By utilizing passive DNS history (e.g., SecurityTrails API) and auditing cloud DNS logs (Route53, Azure, Cloudflare), users can identify persistent attack vectors that survive traditional remediation efforts.