Skip to content
You signed in with another tab or window. to refresh your session.
You signed out in another tab or window. to refresh your session.
You switched accounts on another tab or window. to refresh your session.
Here are
28 public repositories
matching this topic...
👁 CloudPeler
CrimeFlare is a useful tool for bypassing websites protected by CloudFlare WAF, with this tool you can easily see the real IP of websites that have been protected by CloudFlare. The resulting information is certainly very useful for conducting further penetration testing, and analyzing websites with the same server.
a tool to enumerate the resource records of a DNS zone using its DNSSEC NSEC or NSEC3 chain
Advanced kernel-native security framework to disrupt and prevent DNS-based breaches including C2 channels and tunneling with zero data loss. Combines TC, Netfilter, raw socket interception, BPF maps, and ring buffers, runs entirely on eBPF in the Linux kernel. Integrates with deep learning for advanced intelligent EDR
Command-line tool to detect email spoofing vulnerabilities by analyzing SPF and DMARC DNS records. Supports single and bulk domain checks with multiple output formats.
Open-source DNS & email security scanner. One MCP endpoint, 57 checks, zero install. Cloudflare Workers.
Configuration of filtering caching DNS server with DoH/DoH3/DoT/DoQ interfaces and second level cache. Ready for Prometheus, Loki, Promtail, Grafana.
Multi-layer OPSEC failure analysis framework - Research-grade threat modeling and signal correlation
A lightweight tool written in Go to monitor and detect potential DNS exfiltration attempts in real-time. Designed for network security analysis.
Deterministic DNS TXT tunnel detection. Composite anomaly scoring over PCAP and Zeek logs — every score is a decomposable function of six inspectable features. No ML. No black boxes. It computes. It explains.
Bulk domain email security lockdown tool that prevents email phishing and spoofing attacks by automatically configuring SPF hard fail, null MX records, and DMARC rejection policies on unused Cloudflare-managed domains.
Zero-Trust DNS platform with a WFP kernel driver, SHA3-512 integrity enforcement, and ISO 27001 A.8.28 compliant Rust implementation.
An advanced, security-focused network traffic analysis tool designed for system administrators, cybersecurity professionals, and network engineers. The xsukax PCAP Analyzer provides comprehensive insights into network behavior while maintaining strong privacy protections and offering advanced threat detection capabilities.
Multi-layer real-time MITM protection for Linux — blocks ARP poisoning, DNS spoofing, rogue DHCP offers, rogue access points, SSL strip, broadcast poisoning (LLMNR, mDNS, NBNS, WS-Discovery), ICMP redirect exploits, HTTPS to HTTP downgrade attacks
Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping, and remediation via hardened Unbound (DoT) on Arch Linux.
Hardened Ubuntu 25.10 - NextDNS DoH
Secure your online experience with AdGuard Home, your ultimate solution for a clean and safe browsing environment.
Setting up DNS SEC Through Local Resolution Using Docker Containers - An Analysis
CarbolicAcid is a high‑performance CoreDNS security plugin for filtering poisoned DNS responses at the IP layer.
Refuser is a CoreDNS plugin that actively blocks DNS queries matching entries in external rule files. It supports periodic hot‑reload, allowing rule updates to take effect without restarting CoreDNS.
DNSSEC chain-of-trust validator in Python. Verifies DS, DNSKEY and RRSIG records from the root trust anchor to a target domain.
Improve this page
Add a description, image, and links to the
dns-security
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
dns-security
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.