id: dnssec-detection info: name: DNSSEC Detection author: pdteam severity: info description: Domain Name System Security Extensions (DNSSEC) are enabled. The Delegation of Signing (DS) record provides information about a signed zone file when DNSSEC enabled. reference: - - classification: cwe-id: CWE-200 tags: dns,dnssec dns: - name: "{{FQDN}}" type: DS extractors: - type: regex group: 1 regex: - "IN\tDS\t(.+)" # Enhanced by mp on 2022/03/14