Sinkhole
A sinkhole is a controlled destination that security researchers or law enforcement redirect malicious traffic to — often for botnet takedowns. Sinkholed domains and IPs may still appear on threat feeds during transition periods; enrichment context helps avoid blocking legitimate sinkhole operators.
Frequently Asked Questions
What is Sinkhole?
A sinkhole is a controlled destination that security researchers or law enforcement redirect malicious traffic to — often for botnet takedowns. Sinkholed domains and IPs may still appear on threat feeds during transition periods; enrichment context helps avoid blocking legitimate sinkhole operators.
How is Sinkhole related to Botnet?
Sinkhole and Botnet are both key concepts in threat intelligence. A botnet is a network of compromised devices ("bots") controlled by an attacker via a C2 server. Botnets are used for DDoS attacks, spam campaigns, credential stuffing, and ransomware delivery. Individual bots are often unaware they are compromised.
Related Terms
Botnet
A botnet is a network of compromised devices ("bots") controlled by an attacker via a C2 server. Botnets are used for DDoS attacks, spam campaigns, credential stuffing, and ransomware delivery. Individual bots are often unaware they are compromised.
C2 Infrastructure
Command-and-control (C2) infrastructure is the server, domain, or cloud resource malware uses to receive instructions and exfiltrate data. Blocking C2 IPs and domains at the firewall and DNS layer disrupts active infections before lateral movement.
DNS (Domain Name System)
The Domain Name System translates human-readable domain names (like ismalicious.com) into IP addresses. DNS data is a rich source of threat intelligence — malicious domains, fast-flux networks, DNS tunneling, and typosquatting are all detectable via DNS analysis.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.