Skip to content

Passive DNS

Definition

A historical database of DNS resolutions collected by sensors at recursive resolvers or network taps. Passive DNS shows which IP addresses a domain resolved to in the past and when, enabling investigators to reconstruct attacker infrastructure after it has changed.

Data type
Historical DNS resolution records
Source
Sensors at recursive resolvers or network taps
Shows
Which IPs a domain resolved to, and when
Use
Reconstructing attacker infrastructure

Common questions

How does passive DNS differ from a live DNS lookup?+

A live lookup returns only a domain's current resolution, while passive DNS provides a historical record of every IP address a domain has resolved to over time, including infrastructure no longer in use.

Why is historical resolution data valuable for attacker attribution?+

Attackers often reuse hosting infrastructure across campaigns, so passive DNS can link a domain used in one incident to infrastructure seen in earlier or later incidents.

Related terms

A Record
A DNS resource record that maps a domain name to an IPv4 address. The primary attribution record in most investigations. An AAAA...
DNS Tunnelling
Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks...
Domain Generation Algorithm (DGA)
Code embedded in malware that produces a large set of pseudo-random domain names on a scheduled basis. The malware tries each until...
Fast-Flux
An evasion technique in which a domain's A records cycle through a large pool of IP addresses with very short TTL values....
WHOIS
A query protocol that returns registration data for a domain, including registrant name, organisation, email, nameservers, and registration and expiry dates. Since...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.