analyzer-d4-passivedns version 0.5 released as standalone passive DNS server with new COF stream collector
Latestanalyzer-d4-passivedns is an analyzer for a D4 network sensor including a complete Passive DNS server. The analyser can process data produced by D4 sensors (in passivedns CSV format (more to come)) or independently from D4 using COF websocket streams.
A new version of analyzer-d4-passivedns has been released which includes:
- Feeding from COF websocket stream (independently of D4 collection). A sample COF stream (newly seen IPv6 addresses and DNS records) is included in the documentation and kindly provided by CIRCL.
- Add new back-end for large Passive DNS server kvrocks instead of redis