Avatar Avatar

DNS continues to provide one of the clearest windows into activity across the Black Hat network. Since 2017, Cisco has helped secure Black Hat through DNS-layer visibility and protection, providing the Network Operations Center (NOC) / Security Operations Center (SOC) team with an early vantage point into where devices are attempting to connect.

At Black Hat, however, the value of DNS goes well beyond traditional threat blocking. The conference creates a uniquely noisy environment where security research, demos, pen-testing tools, malware analysis and thousands of attendee devices all generate activity that might look suspicious on a typical enterprise network. DNS telemetry gives analysts an important starting point for separating this expected activity from events that deserve further investigation, while also revealing broader trends in how the network is being used.

Building on the encrypted DNS controls introduced at Black Hat USA 2025, this visibility remains particularly important as encrypted protocols and privacy technologies increasingly obscure traditional network telemetry.

Continuing from last year’s priorities to monitor and block resolutions for domains related to the ApateWeb Potentially Unwanted Program (PUP) delivery and phishing campaign, which uses ‘two/three-name’ domain pattern, we did see some of these destinations blocked to protect attendees.

Fig. 1: Blocked resolution requests

DNS Year-Over-Year Statistics

This year, we identified 76,331,133 DNS requests across 1.02 million domains and 1,268 identities, as more attendees connected to the conference network vs recent years. With the increase in DNS requests, we also identified an increase in number of apps:

2019: ~3,600 2023: ~7,500 2026: ~10,800
2021: ~2,600 2024: ~9,300
2022: ~6,300 2025: ~9,300
Fig. 2: Black Hat DNS queries, visualized year-over-year

Key findings

Secure Access was not merely resolving DNS—it was preventing devices from bypassing organizational DNS inspection through unapproved encrypted resolvers

  • mask.icloud.com generated 4.42 million requests, of which 99.7% were blocked.
  • Its 4.42 million blocks represented 79.3% of every blocked DNS request.
  • Apple privacy-relay and encrypted-DNS hostnames collectively accounted for approximately 97.9% of blocks among the top blocked destinations.
  • Other blocked encrypted resolvers include Google DNS, Cloudflare DNS, AdGuard, NextDNS and Quad9.

Cisco classified 8,695 DNS requests as “Hacking.”

  • Volume began with 47 requests on July 31, rose to 2,341 on August 3, remained high through August 5, then dropped to 325 on August 6.
  • Leading destinations strongly suggest labs and education:
    • Cyfinoid.training — 1,458
    • kali.darklab.sh and its service records — 1,380
    • hackerai.co — 542
    • exploit-db.com/www.exploit-db.com — 462
    • ctf.icanhack.nl — 192
    • downloads.metasploit.com — 118
    • interact.sh and app.interact.sh — 101

Tool and research-site footprint

A focused set of penetration-testing and research domains generated approximately 5,137 requests, including:

  • OffSec: 1,436
  • PortSwigger: 1,009
  • HackerOne: 726
  • URLScan: 457
  • TryHackMe: 430
  • VirusTotal: 302
  • Webhook.site: 302
  • Nmap: 130
  • Ngrok: 127
  • Shodan: 42
  • Censys: 23
  • Kali: 5

This view highlights the most visited destinations observed through Cisco Secure Access that were classified under security-related categories, including Command & Control (C2C), Cryptomining, Malware, Phishing, and Potentially Harmful content.

Given the security research, demos, training and testing taking place at Black Hat, traffic to many of these destinations was expected and not necessarily indicative of malicious activity.

Fig. 3: Black Hat 2026 top security-related destinations

Growth of Gen AI

The growth of Generative AI was clearly visible on the Black Hat network, with Cisco Secure Access identifying nearly twice as many GenAI applications compared to last year. This increase highlights how quickly AI-powered tools are becoming part of the everyday application landscape and reinforces the growing need for visibility and governance around their use.

Fig. 4: Cisco App Discovery GenAI

With so many talks incorporating AI subjects, the real-world usage of attendees serves as a metric to measure the increase of adoption and the proliferation of AI tools.

Fig. 5: Top 1-5 GenAI DNS Requests
Fig. 6: Top 6-10 GenAI DNS Requests

Notable observations:

  • Claude exceeded ChatGPT in DNS volume. Together they represented 53.5% of GenAI-associated DNS traffic.
  • The top three apps—Claude, ChatGPT and Cursor—accounted for 67.6% of the GenAI total.
  • GenAI was not limited to chatbots. Application development and testing tools generated 257,321 requests (22.9%), led by Cursor, GitHub Copilot, Windsurf and Cline.
  • Search and conversational applications represented 58.5% of requests; office-productivity AI contributed another 12.5%.
  • Cisco marked 14 apps as high risk, but those apps generated 55% of GenAI DNS volume. “High risk” is Cisco’s application-risk classification, not evidence that the traffic was malicious.

Top DNS Categories

Each year, the NOC leaders give awards for the top requested websites by category. In 2026 we saw Slack hold serve for the top chat app, along with clashes of big names like Apple vs. Google and Tinder vs. Hinge. We’ll present the last matchup with no comment.

Fig. 7: Top DNS Categories

Importance of DNS in Your NOC/SOC

DNS is one of the clearest signals a SOC has, especially in an event environment where endpoints are transient, unmanaged, or only briefly connected. Every device needs DNS to find services, reach applications, and communicate outward, which makes DNS visibility a powerful way to identify suspicious domains, command-and-control patterns, newly observed infrastructure, phishing activity, malware callbacks, and policy violations before they become larger incidents.

For the Black Hat NOC/SOC, Secure Access DNS telemetry gives analysts a high-value control point and an investigative starting point. It helps the team protect attendees while preserving the open nature of the network, enrich detections, and support faster human validation with evidence that is easy to correlate across firewall, Zeek, packet capture, malware analysis, and identity context. In modern Security Operations, DNS is not just a network service. It is a security sensor, an enforcement layer, and one of the fastest paths from “something looks suspicious” to “we understand what happened.”

Check out the other blogs from our team at Black Hat USA 2026.

 

About Black Hat

Black Hat is the cybersecurity industry’s most established and in-depth security event series. Founded in 1997, these annual, multi-day events provide attendees with the latest in cybersecurity research, development, and trends. Driven by the needs of the community, Black Hat events showcase content directly from the community through Briefings presentations, Trainings courses, Summits, and more. As the event series where all career levels and academic disciplines convene to collaborate, network, and discuss the cybersecurity topics that matter most to them, attendees can find Black Hat events in the United States, Canada, Europe, Middle East and Africa, and Asia. For more information, please visit www.BlackHat.com.

Authors

Steve Vida

Cybersecurity Architect

Kaustubh Vajarkar

Cybersecurity Solutions Engineer