Public DNS Feed
A feed of known benign IPs of public DNS servers.
Data Enrichment & Threat Intelligence · Public DNS Feed · Feed
Details
| ID | Public DNS Feed |
|---|---|
| Provider | Open Source |
| Category | Data Enrichment & Threat Intelligence |
| From Version | 5.5.0 |
| Docker Image | demisto/netutils:1.0.0.10187688 |
| Supported Modules | Agentix XSIAM |
README
A feed of known benign IPs of public DNS servers.
Configure Public DNS Feed in Cortex
| Parameter | Description | Required |
|---|---|---|
| url | Public DNS feed URL | True |
| feed | Fetch indicators | False |
| feedReputation | Indicator Reputation | False |
| feedReliability | Source Reliability | True |
| feedExpirationPolicy | False | |
| feedFetchInterval | Feed Fetch Interval | False |
| feedExpirationInterval | False | |
| feedTags | Tags | False |
| feedBypassExclusionList | Bypass exclusion list | False |
| tlp_color | Traffic Light Protocol Color | False |
| Enrichment Excluded | Select this option to exclude the fetched indicators from the enrichment process. | False |
| insecure | Trust any certificate (not secure) | False |
| proxy | Use system proxy settings | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
public-dns-get-indicators
Gets indicators from the feed.
Base Command
public-dns-get-indicators
Input
| Argument Name | Description | Required |
|---|---|---|
| limit | The maximum number of results to return. The default value is 10. Default is 10. | Optional |
Context Output
There is no context output for this command.
Command Example
!public-dns-get-indicators limit=2
Context Example
{
"Indicator": [
{
"rawJSON": {
"type": "IPv6",
"value": "2607:5300:203:1797::53"
},
"score": 0,
"type": "IPv6",
"value": "2607:5300:203:1797::53"
},
{
"rawJSON": {
"type": "Ip",
"value": "199.255.137.34"
},
"score": 0,
"type": "Ip",
"value": "199.255.137.34"
}
]
}
Human Readable Output
Public DNS Feed
value type 2607:5300:203:1797::53 IPv6 199.255.137.34 Ip
Configuration parameters
url— Public DNS feed URL (required)feed— Fetch indicatorsfeedReputation— Indicator ReputationfeedReliability— Source Reliability (required)feedExpirationPolicy—feedFetchInterval— Feed Fetch IntervalfeedExpirationInterval—feedTags— TagsfeedBypassExclusionList— Bypass exclusion listtlp_color— Traffic Light Protocol ColorenrichmentExcluded— Enrichment Excludedinsecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (1)
-
public-dns-get-indicatorsGets indicators from the feed.
category: Data Enrichment & Threat Intelligence provider: Open Source commonfields: id: Public DNS Feed version: -1 configuration: - defaultvalue: https://public-dns.info/nameservers-all.txt display: Public DNS feed URL name: url required: true type: 1 section: Connect - defaultvalue: 'true' display: Fetch indicators name: feed type: 8 required: false section: Collect - additionalinfo: Indicators from this integration instance will be marked with this reputation defaultvalue: Good display: Indicator Reputation name: feedReputation options: - None - Good - Suspicious - Bad type: 18 required: false section: Collect - additionalinfo: Reliability of the source providing the intelligence data defaultvalue: A - Completely reliable display: Source Reliability name: feedReliability options: - A - Completely reliable - B - Usually reliable - C - Fairly reliable - D - Not usually reliable - E - Unreliable - F - Reliability cannot be judged required: true type: 15 section: Collect - defaultvalue: indicatorType name: feedExpirationPolicy display: "" options: - never - interval - indicatorType - suddenDeath type: 17 required: false section: Collect advanced: true - defaultvalue: '240' display: Feed Fetch Interval name: feedFetchInterval type: 19 required: false section: Collect advanced: true - defaultvalue: '20160' display: "" name: feedExpirationInterval type: 1 required: false section: Collect advanced: true - additionalinfo: Supports CSV values. display: Tags name: feedTags type: 0 required: false section: Collect advanced: true - additionalinfo: When selected, the exclusion list is ignored for indicators from this feed. This means that if an indicator from this feed is on the exclusion list, the indicator might still be added to the system. display: Bypass exclusion list name: feedBypassExclusionList type: 8 required: false section: Collect advanced: true - additionalinfo: The Traffic Light Protocol (TLP) designation to apply to indicators fetched from the feed. display: Traffic Light Protocol Color name: tlp_color options: - RED - AMBER - GREEN - WHITE type: 15 required: false section: Collect - display: Enrichment Excluded name: enrichmentExcluded type: 8 required: false additionalinfo: Select this option to exclude the fetched indicators from the enrichment process. defaultvalue: 'false' hidden: - xsoar_on_prem section: Collect - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect advanced: true - display: Use system proxy settings name: proxy type: 8 required: false section: Connect advanced: true description: A feed of known benign IPs of public DNS servers. display: Public DNS Feed name: Public DNS Feed script: commands: - arguments: - defaultValue: '10' description: The maximum number of results to return. The default value is 10. name: limit description: Gets indicators from the feed. name: public-dns-get-indicators dockerimage: demisto/netutils:1.0.0.10187688 feed: true runonce: false script: '-' subtype: python3 type: python tests: - Public_DNS_Feed_Test fromversion: 5.5.0 sectionorder: - Connect - Collect