#1DNS reconnaissance, monitoring, tunneling detection, and DNS security analysis tools.
Kitploit recommended

EDNS Client Subnet (ECS) Remote Detection Tool - CVE-2025-40766
Defensive research notes for CVE-2026-5950, a BIND 9 resolver DoS vulnerability credited to Billy Baraja (BielraX).

Patch for CVE-2017-14491 in dnsmasq 2.4.1, fixing a heap-based buffer overflow in DNS response handling to prevent remote code execution.

PowerDNS CVE-2017-15120 / DO NOT ABUSE

PoC exploit for CVE-2025-5688: remote out-of-bounds write in FreeRTOS-Plus-TCP via crafted LLMNR/mDNS queries, causing crash or potential RCE on…

Single-page tracker recording per-distribution patch status for CVE-2026-81642, the Unbound DNSSEC validator heap overflow and ReTrap complexity…

Automated exploit tool for CVE-2024-23334 that collects domains from certstream, checks for vulnerable Python aiohttp servers, and sends successful…

A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to…

DNS vulnerability exploit for CVE-2023-50387 with automated RRSIG key generation and Docker-based attack simulation against vulnerable and patched…


Proof-of-concept exploit for CVE-2020-8617 targeting BIND DNS servers via TKEY transaction abuse, with Docker-based lab environment for testing.

CVE-2023-1671-POC, based on dnslog platform

mooSocial v3.1.8 is vulnerable to external service interaction on post function.

Proof-of-concept exploit for CVE-2021-23017, a DNS resolver vulnerability in NGINX, demonstrating remote code execution via a crafted DNS response.

PowerShell script to mitigate CVE-2020-1350 (SigRED) by reducing DNS server TCP receive packet size limit and restarting the service.