Skip to content

analyzer-d4-passivedns version 0.5 released as standalone passive DNS server with new COF stream collector

Latest
Compare
Choose a tag to compare
@adulau adulau released this 15 Jul 10:16
· 6 commits to master since this release
v0.5
7bf821d

analyzer-d4-passivedns is an analyzer for a D4 network sensor including a complete Passive DNS server. The analyser can process data produced by D4 sensors (in passivedns CSV format (more to come)) or independently from D4 using COF websocket streams.

A new version of analyzer-d4-passivedns has been released which includes:

  • Feeding from COF websocket stream (independently of D4 collection). A sample COF stream (newly seen IPv6 addresses and DNS records) is included in the documentation and kindly provided by CIRCL.
  • Add new back-end for large Passive DNS server kvrocks instead of redis