Spots DNS tunnelling and data exfiltration, malicious resolvers, and domains used for phishing or command and control. This protection now ships within Defender for Servers Plan 2.
Also called Defender for DNS.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Defender for DNS in context, with comparison tables and the common traps.
Terms in this definition
- DNS
The system that turns names into addresses. In Azure, private endpoints depend on private DNS zones, which are queried through 168.63.129.16.
- C2
Command and control: servers and channels through which an attacker directs compromised devices and receives stolen data. Investigators can spot it from the network connections recorded in an investigation package.
- Defender for Servers Plan 2
Top Defender for Servers tier, which includes FIM, JIT VM access, agentless scanning and, from August 2023, Defender for DNS alerts. You turn it on per subscription or per Log Analytics workspace.
Related terms
- Microsoft Defender for Servers
Covers Arc-enabled servers and Azure VMs in Defender for Cloud. Plan 1 brings integration with Defender for Endpoint; Plan 2 goes further with agentless scanning, file integrity monitoring and alerts from Defender for DNS.