Passive DNS
Definition
A historical database of DNS resolutions collected by sensors at recursive resolvers or network taps. Passive DNS shows which IP addresses a domain resolved to in the past and when, enabling investigators to reconstruct attacker infrastructure after it has changed.
- Data type
- Historical DNS resolution records
- Source
- Sensors at recursive resolvers or network taps
- Shows
- Which IPs a domain resolved to, and when
- Use
- Reconstructing attacker infrastructure
Common questions
How does passive DNS differ from a live DNS lookup?+
A live lookup returns only a domain's current resolution, while passive DNS provides a historical record of every IP address a domain has resolved to over time, including infrastructure no longer in use.
Why is historical resolution data valuable for attacker attribution?+
Attackers often reuse hosting infrastructure across campaigns, so passive DNS can link a domain used in one incident to infrastructure seen in earlier or later incidents.
Related terms
- A Record
- A DNS resource record that maps a domain name to an IPv4 address. The primary attribution record in most investigations. An AAAA...
- DNS Tunnelling
- Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks...
- Domain Generation Algorithm (DGA)
- Code embedded in malware that produces a large set of pseudo-random domain names on a scheduled basis. The malware tries each until...
- Fast-Flux
- An evasion technique in which a domain's A records cycle through a large pool of IP addresses with very short TTL values....
- WHOIS
- A query protocol that returns registration data for a domain, including registrant name, organisation, email, nameservers, and registration and expiry dates. Since...