03/01/2026
๐น DHCP (Dynamic Host Configuration Protocol) in IT Forensics
๐ What DHCP Does
DHCP automatically assigns:
IP Address
MAC-to-IP mapping
Gateway & DNS server
Lease time
to devices when they connect to a network.
๐ต๏ธ How DHCP Helps in IT Forensics
1๏ธโฃ Device Identification
Helps identify which device was using a specific IP address at a given time
Maps MAC Address โ IP Address โ Timestamp
2๏ธโฃ User Activity Tracking
Useful when multiple users share the same network
Determines who joined the network and when
3๏ธโฃ Incident Timeline Creation
DHCP lease logs help build a time-based forensic timeline
4๏ธโฃ Insider Threat Investigation
Detects unauthorized or unknown devices connected to the network
๐น DNS (Domain Name System) in IT Forensics
๐ต๏ธ How DNS Helps in IT Forensics
1๏ธโฃ Malicious Domain Detection
Identifies connections to phishing, malware, or C2 servers
2๏ธโฃ User Browsing Behavior Analysis
Shows which domains were accessed, even if content is encrypted
3๏ธโฃ Malware Investigation
Malware often communicates using DNS
Suspicious or rare domains are strong indicators
4๏ธโฃ Data Exfiltration Detection
DNS tunneling can be detected through abnormal DNS queries
๐ก๏ธ Why Both Are Critical in IT Forensics
DHCP answers:
๐ โWhich device was on the network?โ
DNS answers:
๐ โWhere did that device communicate?โ
Together, they provide complete visibility during investigations.
๐ฑ For Tech & Security Professionals
Strong forensic analysis is not only about tools โ
itโs about understanding network fundamentals deeply.