As cited
Copy frozen at (site build).
threat intel
More Odd DNS Records: NIMLOC
DNS resource record type 32 (NIMLOC) is historically assigned to obsolete protocols but continues to appear in network logs, particularly from macOS systems broadcasting NetBIOS name announcements on port 137. The record type was originally designated for Nimrod routing architecture but is now primarily associated with legacy NetBIOS traffic, a protocol largely replaced by modern DNS and SMB implementations on contemporary networks.
Why it matters: Security practitioners monitoring DNS logs should recognize NIMLOC queries as benign legacy NetBIOS traffic from macOS systems rather than indicators of compromise, avoiding false positives while remaining alert to unexpected sources of these outdated protocol broadcasts.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
More Odd DNS Records: NIMLOC
DNS resource record type 32 (NIMLOC) is historically assigned to obsolete protocols but continues to appear in network logs, particularly from macOS systems broadcasting NetBIOS name announcements on port 137. The record type was originally designated for Nimrod routing architecture but is now primarily associated with legacy NetBIOS traffic, a protocol largely replaced by modern DNS and SMB implementations on contemporary networks.
Why it matters: Security practitioners monitoring DNS logs should recognize NIMLOC queries as benign legacy NetBIOS traffic from macOS systems rather than indicators of compromise, avoiding false positives while remaining alert to unexpected sources of these outdated protocol broadcasts.
- Source published
- First seen by Cybersecurity Tracker