• Events & Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
  • Events & Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
HBS logo
HBS Logo
  • Infrastructure
    • CLOUD

      • Cloud Solutions
      • Public Cloud
      • Hybrid Cloud
      • Infrastructure as a Service
      • Cloud Security Solutions
      • Backup, Replication and Disaster Recovery
      • HBS Cloud Hosting Services

      DATA CENTER

      • Data Center Solutions
      • Traditional Data Center
      • Hyperconverged
      • Colocation
      • Directory Services
      • Cloud Email and Calendar Solutions

      NETWORK AND ACCESS

      • Network Infrastructure
      • Enterprise Mobility
      • Wireless Solutions
      • SD-WAN
      • Structured Cabling
      • Staff Augmentation
  • Managed Services
    • MANAGED ONE

      • Managed One Overview
      • Managed Backup and Disaster Recovery
      • Managed Email and Collaboration Security
      • Managed Firewall

       

      • Managed HaaS and SaaS
      • Managed IT Help Desk
      • Managed Network and Server Monitoring

      HBS + PARTNER SOLUTIONS

      • HBS Secure with Verkada
      • HBS Collaborate with Webex
      • Managed XDR
      HBS Managed One Megamenu Graphic
  • Modern Workplace
    • MICROSOFT

      • Microsoft Licensing Management
      • Microsoft Modern Workplace
      • Microsoft Fabric
      • Microsoft Funding Opportunities

       

      • Dynamics 365 Business Central
      • Dynamics 365
      • Dynamics GP

      COLLABORATION

      • Audio Visual
      • Unified Communication Solutions
      • HBS Collaborate with Webex
  • Professional Services
    • ADVISORY

      • Virtual CISO
      • Virtual CIO
      • Project Management
      • IT Business Consulting

      ENGINEERING SERVICES

      • Staff Augmentation

      AI & ANALYTICS

      • Artificial Intelligence
      • AI Advance
      • AI Predict
      • AI Assist
      • Data Management and Analytics
      • Microsoft Fabric

      APPLICATION INNOVATION

      • Website Development
      • Application Development

      DOCUMENT MANAGEMENT

      • Document Management Services
      • Document and Check Scanners
  • Security
    • CYBERSECURITY

      • Managed XDR
      • Penetration Testing
      • Vulnerability Scanning
      • Email Security Services
      • Digital Forensics and Incident Response
      • Backup, Replication and Disaster Recovery
      • Firewalls
      • Cloud Security Solutions

       

      • Virtual CISO
      • Virtual Security Team
      • Virtual Security Engineer
      • Cybersecurity Risk Assessment
      • Governance and Compliance
      • SOC 2
      • CMMC
      • Managed Security Awareness Training

      PHYSICAL SECURITY

      • Security Solutions
      • HBS Secure with Verkada
      Cybersecurity Risk Assessment Megamenu Graphic
  • Search
Contact Us
Blog

DNS and DHCP Logs Are Critical To Breach Investigations

  • Written by: Dave Nelson
  • May 6, 2015

Breach investigations are by their nature somewhat chaotic. There is a flurry of activity by the HR, IT, Legal, Communications and line of business departments. The ability to quickly determine what happened, who or what was impacted and what the next steps are can be thwarted by a lack of information. Logs are critical in helping understand all aspects of a breach. 

In the past we have talked about the importance of logs from firewalls, routers and layer 3 switches, server or workstation event logs and intrusion detection logs. Two logs which are commonly overlooked are DNS and DHCP logs. 

At 2am in the morning it is much easier to simply pull up a DHCP log and determine that machine HQ5678A was assigned 10.1.25.163 on 03/03/2015 at 9:53am rather than having to query registry entries or sift through event logs hoping to find a trace.  It is also helpful if systems hold their DHCP leases for 30 days or longer. It keeps the logs shorter and helps investigators more easily spot trends of activity, whether that be normal or abnormal activity. 

It is also easier to have firewalls record DNS entries and have the log contain both an IP address along with a DNS entry so you can quickly tell that a user on computer HQ5678A was using ebay on port 443 versus a virus using port 443 to communicate with hackme dot com that same port. Much time is spent tracking an IP address to a hostname simply to discover that the communication is to or from a known and approved host. 

Time is something you have precious little of during a cyber-security or breach investigation. Taking action before the security investigation begins can save you a lot of time and keep you from running down rabbit trails during your investigation. 

Related Content

HBS. One Partner. Endless Possibilities

Digital Forensics and Incident Response

Rapidly address cyber threats with our Digital Forensics and Incident Response services: Quick mitigation and restoration, trusted guidance, 24x7x365 support.

Learn More »
Digital Forensics Graphic with Puzzle Pieces

Digital Forensics Best Practices: How to Prepare Before a Breach

The best digital forensics investigators learn as much from what’s missing as what’s there. Here is what to look for in any investigation.

Explore More »
Alarm Clock and Coins Time is Money Graphic

Why Quick Responses to Data Breaches Save You Money

Most data breaches get more expensive with each passing day. That’s why HBS incident response team keeps its calendar open on Friday afternoons.

Read More »
  • Data Safety, Digital Forensics, Disaster Recovery
Blog

Connect:

[email protected]  |  800.236.7914

HBS logo

HQ | 1700 Stephen Street
Little Chute, WI 54140
Locations

HBS Remote Support | Service & Technical Support | E-Bill Portal
Standard Terms & Conditions | Cookie Policy | Privacy Policy | Onboarding Form | End User Agreements | E-Bill FAQ | Site Map
Any purchase is governed by the HBS Standard Terms and Conditions.
©2026 Heartland Business Systems. All rights reserved.

Halo from HBS
This chat may be recorded as described in our Privacy Policy.