Knowledge / dns detection threat-intel

Passive DNS

Historical DNS answers observed by sensors. Pivot on an IOC. Not a replacement for a live lookup.

Passive DNS is a record of what names resolved to in the past, collected from resolvers or sensors that see real traffic. Given an IP, you list names that pointed there. Given a name, you see old answers and first or last seen.

It is not a live lookup and it is not complete. What your sensors never saw is missing. Use it to pivot indicators and to tell a new name from one with years of boring mail records. Then still check the live answer.

See also: DNS, Indicator of compromise, Threat intelligence, Fast flux.