CERN-CERT / pDNSSOC

Leveraging MISP indicators via a pDNS-based infrastructure as a poor man’s SOC.
MIT License
49 stars 5 forks source link

Move to Python correlator (pdnssoc-cli) and enhanced DNS collector #13

Closed arvchristos closed 1 year ago

arvchristos commented 1 year ago

This MR is the starting point to move away from fluentd and Ruby in favor of a more mature python correlator (pdnssoc-cli) and a more performant collector supporting dnstap (go-dnscollector).

Our intention is to use this repository as the deployment schematic for pDNSSOC, by leveraging various tools that can act on top of DNS logs collected by go-dnscollector.