
Sometimes it only takes one look-alike domain name to instigate the penetration of an entire network. Investigators now have additional choices for analyzing suspicious domain names and IP addresses with enhanced DNSDB search options.
According to the 2019 Verizon DBIR, the gap between compromise and detection remains wide — more than half of the breaches took months to discover. Abusing the Domain Name System (DNS) is one way cybercriminals remain stealth. For example, they will buy, use, and discard thousands of domain names for their malicious campaigns. They also “hide in plain sight” by sharing DNS-assets used by other bad guys.
Farsight Security DNSDB®, the world’s largest historical Passive DNS database, is used by Fortune 500 and government agency security teams around the world to uncover shared malicious infrastructure and gain new insights on today’s threats. The breadth of our geographical coverage, wide range of DNS records and high performing, scalable infrastructure has made DNSDB the leading passive DNS solution. Yet since a single query to the database can deliver up to a million responses or more, investigators needed the ability to access information specific to their incident more quickly and easily.
Farsight Security is continuously developing new ways to increase the value and usability of its real-time and historical DNS Intelligence data for its customers. Today Farsight Security has announced the following new DNSDB search features:

Figure 1. DNSDB Scout is one of the many ways you can access the Volume Across Time feature to see if a record was observed heavily over shorter periods of time.

Figure 2. Estimation of Result Size enables a single results snapshot for a givenquery.

Figure 3. The Incremental Result Transfers feature allows queries to go beyond a client’sresults limit.
This newly enhanced version of DNSDB is now available to all DNSDB customers. Customers can query DNSDB directly via the RESTful API at https://api.dnsdb.info, or by utilizing one of the many DNSDB API Clients and integrations. DNSDB Scout, Farsight’s browser extension for both Google Chrome and Mozilla Firefox, has been updated to support the new features, and can be downloaded from the Google Chrome Web Store or the Mozilla Firefox Add-Ons site respectively.
dnsdbq
, Farsight’s command line client written in C, has also been updated and is available on GitHub.
If you would like to learn more about DNSDB, please visit Farsight Security at Black Hat USA at Booth #1303 next week or our Get Started page, where you can also signup for a free 30-day trial API key. You can also contact our sales team at [email protected].
Karen Burke is the Director of Corporate Communications for Farsight Security, Inc.