From 39ad0b0f680f302a6a823e9f49fe64956fbd694f Mon Sep 17 00:00:00 2001 From: Rishi Date: Sun, 17 Mar 2024 12:54:28 +0000 Subject: [PATCH] soa-detection --- dns/soa-detect.yaml | 79 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 79 insertions(+) create mode 100644 dns/soa-detect.yaml diff --git a/dns/soa-detect.yaml b/dns/soa-detect.yaml new file mode 100644 index 0000000000..d2fef30649 --- /dev/null +++ b/dns/soa-detect.yaml @@ -0,0 +1,79 @@ +id: soa-detect + +info: + name: SOA record service detection + author: rxerium + severity: info + description: Detects which domain provider a domain is using, detected through SOA records + reference: + - https://www.cloudflare.com/learning/dns/dns-records/dns-soa-record/ + metadata: + max-request: 1 + tags: dns,soa + +dns: + - name: "{{FQDN}}" + type: SOA + matchers-condition: or + matchers: + - type: word + name: "Cloudflare" + words: + - "dns.cloudflare.com" + + - type: word + name: "Amazon Web Services" + words: + - "awsdns" + + - type: word + name: "Akamai" + words: + - "hostmaster.akamai.com" + + - type: word + name: "Azure" + words: + - "azure-dns.com" + + - type: word + name: "NS1" + words: + - "nsone.net" + + - type: word + name: "Verizon" + words: + - "verizon.com" + + - type: word + name: "Google Cloud Platform" + words: + - "googledomains.com" + - "google.com" + + - type: word + name: "Alibaba" + words: + - "alibabadns.com" + + - type: word + name: "Safeway" + words: + - "safeway.com" + + - type: word + name: "Mark Monitor" + words: + - "markmonitor.com" + - "markmonitor.zone" + + - type: word + name: "Hetznet" + words: + - "hetzner.com" + + - type: word + name: "Edge Cast" + words: + - "edgecastdns.net" \ No newline at end of file