Skip to content

tylabs/dovehawk_dns

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Dovehawk.io Passive DNS Collector Module for Zeek

This module colects DNS requested names and multiple answers across an entire Cluster or Standalone Zeek instance. The requestor is not tracked and SUMSTATS is used to aggregate multiple requests over a specified time period anonymizing the requests.

Local hostnames are stripped to further anonymize the data for external sharing.

Sticker 1 Sticker 2

Screencaps

DoveHawk pDNS Reported

Dovehawk pDNS Reports

DoveHawk pdns.log Local Log

Dovehawk pDNS Log

Requirements

Zeek > 3.0

Curl command line version used by ActiveHTTP

Database

See dovehawk_lambda for an AWS Lambda serverless function to store reporting in RDS Aurora.

Contact

Tyler McLellan @tylabs

Releases

No releases published

Packages

No packages published

Languages