mosajjal / dnsmonster

Passive DNS Capture and Monitoring Toolkit
https://dnsmonster.dev
GNU General Public License v3.0
314 stars 53 forks source link

Support for PassiveDNS - common output format #30

Open mosajjal opened 2 years ago

mosajjal commented 2 years ago

https://datatracker.ietf.org/doc/draft-dulaunoy-dnsop-passive-dns-cof/

looks like a cool idea to implement

mosajjal commented 1 year ago

Also worth exploring @miekg's rfc8618 as an output format (CBOR).

mosajjal commented 1 year ago

OCSF: https://schema.ocsf.io/classes/dns_activity