Skip to content

Conversation

@emilhf
Copy link
Contributor

@emilhf emilhf commented Aug 15, 2020

While this does make this object slightly more similar to the passive-dns object, I would argue that the purpose is different: The passive DNS object models aggregated DNS intelligence, whereas the dns-record object deals with observables noted by the analyst. There also might be other record types that should be added, but this should deal with the most common ones.

Common use cases for these new record types include:

  • Tracking emails from all valid SPF senders used by a spammer (TXT or SPF)
  • Correlating validation tokens (TXT) across multiple fronting domains
  • Tracking load balanced infrastructure exposed via SRV records, i.e. cloud stuff.
  • Modelling CNAME chains

@adulau adulau merged commit bc4cabb into MISP:main Aug 15, 2020
@adulau
Copy link
Member

adulau commented Aug 15, 2020

Thank you very much! It makes sense.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants