Passive DNS
Passive DNS records historical resolutions between domain names and IP addresses collected from recursive resolvers and sensors. Analysts use passive DNS to pivot from a malicious IP to related domains, identify fast-flux patterns, and timeline infrastructure changes.
Frequently Asked Questions
What is Passive DNS?
Passive DNS records historical resolutions between domain names and IP addresses collected from recursive resolvers and sensors. Analysts use passive DNS to pivot from a malicious IP to related domains, identify fast-flux patterns, and timeline infrastructure changes.
How is Passive DNS related to DNS History?
Passive DNS and DNS History are both key concepts in threat intelligence. DNS history is a record of historical DNS resolution data for a domain — including all IP addresses it has ever resolved to, when changes occurred, and what nameservers have been used. It is used in threat investigations to trace infrastructure reuse and identify related malicious domains.
Related Terms
DNS History
DNS history is a record of historical DNS resolution data for a domain — including all IP addresses it has ever resolved to, when changes occurred, and what nameservers have been used. It is used in threat investigations to trace infrastructure reuse and identify related malicious domains.
Fast Flux
Fast flux is a DNS technique used by attackers to rapidly change the IP addresses associated with a domain — sometimes cycling through hundreds of IPs within minutes. It is used to make C2 servers and phishing sites resistant to IP-based blocking and takedowns.
Reverse IP Lookup
Reverse IP lookup returns all domain names hosted on a given IP address. It is used by threat hunters to identify other malicious domains sharing the same hosting infrastructure as a known bad actor — a technique known as infrastructure pivoting.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.