article thumbnail

What is Passive DNS and how do you leverage it in research?

CTOvision

The concept was created in 2004 to help mitigate the threat of malware but is now used for that and far more use cases. The basic Passive DNS architecture is a replication technique where inter-server DNS messages are captured by sensors. Bob Gourley. Passive DNS has become one of the most powerful tools in the defenders arsenal.