#1DNS reconnaissance, monitoring, tunneling detection, and DNS security analysis tools.
Kitploit recommended

Security checks for your researches

Zeek script to detect servers vulnerable to CVE-2020-13777

CVE-2025-24813_POC

cupntlm

Proof-of-concept exploit for CVE-2018-5740, a denial-of-service vulnerability in BIND DNS server triggered by a crafted DNAME query, with…

In‑depth technical analysis of CVE‑2026‑41096, a critical heap overflow in Windows DNSAPI.dll enabling remote code execution via crafted DNS…

Exploit for TSIG bypass vulnerabilities in Bind (CVE-2017-3143) and Knot DNS (CVE-2017-11104)

This script checks if each domain from a given domain list is vulnerable to CVE-2006-0987

Proof-of-concept exploit for CVE-2021-23017 targeting a remote host with a custom DNS server. Designed for security testing and vulnerability…

Fix for undefined method each in Metasploit’s bailiwicked_domain.rb (CVE-2008-1447 DNS cache poisoning module)

vulnerability in NGINX servers (versions 0.6.18–1.20.0). The scripts aim to cause a Denial of Service (DoS) by sending malicious DNS responses, with…

Generate the poc for CVE-2026-4893: broken EDNS Client Subnet validation.

Single-page tracker recording per-distribution patch status for CVE-2026-81642, the Unbound DNSSEC validator heap overflow and ReTrap complexity…

A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering

DNSpooq - dnsmasq cache poisoning (CVE-2020-25686, CVE-2020-25684, CVE-2020-25685)

Code for blogpost: https://outflank.nl/blog/2018/10/25/building-resilient-c2-infrastructues-using-dns-over-https/

Proof-of-concept Denial of Service exploit for CVE-2020-1350 (SIGRed) targeting Windows DNS servers via crafted DNS SIG records. Includes PCAP for…