<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Honey pot recommendation for DNS sink holing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/honey-pot-recommendation-for-dns-sink-holing/m-p/504339#M105501</link>
    <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are seeing many DNS alerts for spyware, but we don't have any DNS logs.&lt;/P&gt;&lt;P&gt;Also, internal hosts can't resolve external FQDNs, so probably most of the requests are coming from the proxy.&lt;/P&gt;&lt;P&gt;So we are thinking about setting up DNS sink holing with a honey pot.&lt;/P&gt;&lt;P&gt;Any recommendations what to use as a honey pot so that we can get the most information possible from the client connecting to it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Andreas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jun 2022 21:33:18 GMT</pubDate>
    <dc:creator>idelconsulting</dc:creator>
    <dc:date>2022-06-16T21:33:18Z</dc:date>
    <item>
      <title>Honey pot recommendation for DNS sink holing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/honey-pot-recommendation-for-dns-sink-holing/m-p/504339#M105501</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are seeing many DNS alerts for spyware, but we don't have any DNS logs.&lt;/P&gt;&lt;P&gt;Also, internal hosts can't resolve external FQDNs, so probably most of the requests are coming from the proxy.&lt;/P&gt;&lt;P&gt;So we are thinking about setting up DNS sink holing with a honey pot.&lt;/P&gt;&lt;P&gt;Any recommendations what to use as a honey pot so that we can get the most information possible from the client connecting to it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Andreas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 21:33:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/honey-pot-recommendation-for-dns-sink-holing/m-p/504339#M105501</guid>
      <dc:creator>idelconsulting</dc:creator>
      <dc:date>2022-06-16T21:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Honey pot recommendation for DNS sink holing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/honey-pot-recommendation-for-dns-sink-holing/m-p/504573#M105516</link>
      <description>&lt;P&gt;Not a honeypot but Pi-Hole is what I use for both DNS sinkhole and primary DNS server in some cases.&amp;nbsp; I run it in VMware on CentOS8 or on a Raspberry Pi.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 20:25:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/honey-pot-recommendation-for-dns-sink-holing/m-p/504573#M105516</guid>
      <dc:creator>Buck_Smooth</dc:creator>
      <dc:date>2022-06-17T20:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Honey pot recommendation for DNS sink holing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/honey-pot-recommendation-for-dns-sink-holing/m-p/504969#M105544</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;DNS logs are a big deal. Have you looked into the following article to ensure sinkhole setup correctly and logging correctly:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGECA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGECA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I recommend using a secure DNS resolver for anything external.&lt;/P&gt;
&lt;P&gt;Here is a link to a video I made for a conference about DNS:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://youtu.be/ROIAYSEbTuo" target="_blank"&gt;https://youtu.be/ROIAYSEbTuo&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 17:12:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/honey-pot-recommendation-for-dns-sink-holing/m-p/504969#M105544</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-06-20T17:12:12Z</dc:date>
    </item>
  </channel>
</rss>

