#1DNS reconnaissance, monitoring, tunneling detection, and DNS security analysis tools.
Kitploit recommended

loudong

CVE-2017-12865 exploit

PowerDNS CVE-2017-15120 / DO NOT ABUSE

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go NIDS (Network intrusion detection system).

Real-time OSINT intelligence dashboard: 7 live data sources (aircraft, AIS vessels, seismic, fires, weather, GDELT events, news) on an interactive…

Multithreaded Python scanner that detects Log4Shell (CVE-2021-44228) by sending crafted HTTP requests with JNDI payloads and monitoring DNS callbacks…

Scan and analyze Tor hidden services (.onion) to extract metadata, SSH banners, email addresses, and potential IP leaks via mod_status, with a…

Registry-based mitigation script for CVE-2020-1350 Windows DNS Server RCE vulnerability, applying Microsoft's recommended workaround without server…

Patch for CVE-2017-14491 in dnsmasq 2.4.1, fixing a heap-based buffer overflow in DNS response handling to prevent remote code execution.

This tool uses a combination of dictionary-based wordlists (brute-force) and DNS resolution checks to verify the existence of subdomains.

Plan v3 US-6: coredns-style fork fixture for Scanner E2E (CVE-2023-39325)

Knot Resolver CVE-2018-10920 / DO NOT ABUSE

Patched version of dnstracer fixing CVE-2017-9430 stack-based buffer overflow via argv[0] length validation. Traces DNS server chains for hostname…

This experiment is destinated to demonstrate how the DNS rebinding attack works on an emulated IoT. In the setup, we have a simulated IoT device,…

A powershell script to deploy the registry mitigation key for CVE-2020-1350

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

Proof-of-concept exploit for CVE-2022-27438, demonstrating remote code execution via spoofed update server in Advanced Installer 19.3. Includes DNS…