ioc2rpz server x86
Product Overview
ioc2rpz: Where Threat Intelligence Meets DNS
DNS is the control plane of the Internet with unprecedented detailed views on applications, devices and even transferred data going in and out of a network. 80% of malware uses DNS to communicate with Command & Control for DNS data exfiltration/infiltration and phishing attacks using lookalike domains. Response Policy Zones or DNS Firewall is a feature which allows us to apply security policies on DNS. Commercial DNS Firewall feeds providers usually do not allow users to generate their own feeds.
ioc2rpz is a DNS server which automatically creates, maintains and distributes DNS Firewall feeds from various local (files, DB) and remote (http, ftp, rpz) sources. This enables easy integrations with Threat Intel providers and Threat Intelligence Platforms. The feeds can be distributed to any open source and commercial DNS servers which support DNS Firewall/RPZ (Response Policy Zones), e.g. ISC BIND, PowerDNS, Infoblox, BlueCat, Efficient IP etc. With ioc2rpz you can create your own feeds, actions and prevent undesired communications before they happen.
ioc2rpz technology was presented at BlackHat Arsenal 2019/2020 and DefCon Demo Labs 26/27
Version
By
ioc2rpzVideo
Categories
Operating System
Linux/Unix, Ubuntu 20.04
Delivery Methods