a tool to enumerate the resource records of a DNS zone using its DNSSEC NSEC or NSEC3 chain
-
Updated
Mar 6, 2023 - Python
a tool to enumerate the resource records of a DNS zone using its DNSSEC NSEC or NSEC3 chain
Multi-layer OPSEC failure analysis framework - Research-grade threat modeling and signal correlation
The DNS Poisoning Detector is a Python-based tool designed to monitor DNS traffic, detect potential DNS poisoning attacks, and generate detailed PDF reports of its findings.
Python CLI for authorized security-readiness checks of websites, email domains, and local repositories.
Public DNS blocklists, exact-host security feeds, RPZ policies, and optional hardening outputs for Pi-hole, AdGuard Home, Unbound, and NextDNS
Subdomain takeover & DNS vulnerability scanner — takeover detection, email security (SPF, DMARC, DKIM), stale DNS, CORS misconfig, DNSSEC, sinkhole hijack, WAF bypass, origin IP discovery. Async, high-accuracy, bug bounty ready.
EARWIG is an Advanced DNS Exfiltration Research Tool designed for cybersecurity professionals to analyze covert DNS communication channels, study data transfer techniques, and improve network defense strategies. Built for ethical security research, penetration testing labs, and defensive analysis of DNS-based threats in controlled environments.
An advanced, security-focused network traffic analysis tool designed for system administrators, cybersecurity professionals, and network engineers. The xsukax PCAP Analyzer provides comprehensive insights into network behavior while maintaining strong privacy protections and offering advanced threat detection capabilities.
Domain and security monitoring system
StrataScan is a gray-hat hackers attack-surface reconstruction engine that transforms web history into actionable security intelligence. It combines OSINT, archive forensics, DNS/TLS analysis, subdomain discovery, secret detection, temporal diffing, live verification, evidence correlation, and automated reporting.
⚔️ DNS Fighter – A powerful multi‑threaded Windows tool to prevent DNS poisoning, compare 4 DNS resolvers, test 7 protocols, and auto‑update the hosts file. | ابزاری قدرتمند و چندریسمانی برای ویندوز که از حملات مسمومیت دیاناس جلوگیری میکند، خروجی چهار سرور دیاناس را مقایسه مینماید، هفت پروتکل مختلف را آزمایش کرده و فایل «هاست» را بروز میکند
11-layer email security scanner with spoofability scoring (0-100). Checks SPF, DKIM, DMARC, MTA-STS, DANE, BIMI, Ghost-Sender, EchoSpoofing, BreakSPF, and more. One command. One answer: SPOOFABLE or PROTECTED.
Defensive research notes for CVE-2026-5950, a BIND 9 resolver DoS vulnerability credited to Billy Baraja (BielraX).
Local-first asynchronous OSINT and digital-forensics toolkit for DNS, TLS, web, mail and SQLite-backed TF-IDF correlation.
Enterprise DNS threat detection & network forensics platform. Identifies covert data exfiltration and tunneling from raw PCAP/PCAPNG traffic using hybrid machine learning (FastAPI, Scikit-Learn, React).
Educational Pi-hole style DNS sinkhole with blocklists, cache, DoH upstream, live dashboard, and an offensive DNS lab (tunneling + cache poisoning)
AI-augmented threat detection sidecar for Pi-hole — heuristic DGA, NXDOMAIN, volume, and beacon detection on the query log
Multi-layer real-time MITM protection for Linux — blocks ARP poisoning, DNS spoofing, rogue DHCP offers, rogue access points, SSL strip, broadcast poisoning (LLMNR, mDNS, NBNS, WS-Discovery), ICMP redirect exploits, HTTPS to HTTP downgrade attacks
Deterministic, AI-free control plane that turns threat evidence into cautious network enforcement decisions for critical infrastructure.
ST-Hunter: A powerful tool for detecting subdomain takeover vulnerabilities. Features subdomain enumeration (Subfinder, Shodan, crt.sh, etc.), brute-force scanning, AXFR testing, concurrent DNS lookups, and silent mode. Ideal for security researchers and pentesters.
To associate your repository with the dns-security topic, visit your repo's landing page and select "manage topics."