Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Responder: Block a "domain" observable via BIND RPZ DDNS update #435

Closed
mhexp opened this issue Mar 1, 2019 · 2 comments
Closed

Responder: Block a "domain" observable via BIND RPZ DDNS update #435

mhexp opened this issue Mar 1, 2019 · 2 comments
Labels
category:enhancement Issue is related to an existing feature to improve category:new-responder
Milestone

Comments

@mhexp
Copy link
Contributor

mhexp commented Mar 1, 2019

Request Type

Responder

I've built, tested and deployed a responder that takes a Hive observable of type "domain" and adds it to a BIND Response Policy Zone (RPZ), effectively blocking access to the hostname.

My use case involves creating an A record in the RPZ and answering queries with an internal IP that acts as quarantine so we can see which systems are trying to access observed and blocked hostnames.

The responder configuration items allow for setting the following parameters: DNS server IP, TSIG key name, TSIG key value, TSIG hash algorithm, RPZ zone name, and IP address to inject into responses.

I would like to submit this responder for inclusion into the project. I'm still working on attaining organizational approval to share this code.

@3c7 3c7 added category:enhancement Issue is related to an existing feature to improve category:new-responder labels Mar 2, 2019
@mhexp
Copy link
Contributor Author

mhexp commented Jun 21, 2019

Oh in case anyone is waiting based on my initial issue text, I have organizational approval to share this code with the community. I'm hoping it helps others as the hive has been greatly useful to my CIRT.

@jeromeleonard jeromeleonard added this to the 2.2.0 milestone Jun 29, 2019
@jeromeleonard
Copy link
Contributor

thank you for your contribution

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:enhancement Issue is related to an existing feature to improve category:new-responder
Projects
None yet
Development

No branches or pull requests

3 participants