Mar 08 2023 04:54 AM - edited Mar 09 2023 01:02 AM
Hello,
the Microsoft Learn documentation states that MDI monitors all DNS requests that are performed against the domain controller. I wonder how this is done. Via event logs or DNS log file or ... ?
Is there perhaps a blog article on how MDI works under the hood?
Cheers
Martin
Mar 09 2023 03:32 AM
Can you help me out on this one @Martin_Schvartzman ?
Mar 22 2023 01:48 PM
SolutionThe MDI sensor also listens to the network traffic, so it can see the DNS queries from the network packets by the protocol (and/or port).
Mar 23 2023 12:52 AM - edited Mar 23 2023 01:00 AM
That is interessting. What could be wrong if it doesnt or rather does only get a few of all DNS queries? (not standalone)
Mar 27 2023 05:18 AM
Mar 27 2023 05:24 AM
May 08 2023 01:36 AM
Mar 22 2023 01:48 PM
SolutionThe MDI sensor also listens to the network traffic, so it can see the DNS queries from the network packets by the protocol (and/or port).