Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ioc2rpz — ioc2rpz is a place where threat intelligence meets DNS. | Kitploit
Tools/GitHubGitHub/homas/ioc2rpz
Defensive ToolsIndicator of Compromise (IOC) ManagementNetwork SecurityMalware AnalysisThreat IntelligenceIntrusion DetectionDNS FuzzingIncident ResponseDNS Analysis
GitHubhomas/ioc2rpz

ioc2rpz

ioc2rpz is a place where threat intelligence meets DNS.

11621242 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

ioc2rpz™ makes your threat intelligence actionable

License Erlang/OTP Docker Hub

Table of Contents

  • Short Summary
  • Overview
  • ioc2rpz™ is a place where threat intelligence meets DNS
  • Architecture Overview
  • How to use ioc2rpz™
  • ioc2rpz™ web interface
  • Protocol Support
    • Port Summary
    • UDP (Port 53)
    • TCP (Port 53)
    • DNS over TLS / DoT (Port 853)
    • DNS over HTTPS / DoH (Port 443/8443)
    • Rate Limiting
    • DNS NOTIFY
  • ioc2rpz™ vs ISC BIND vs other DNS
  • Installation
  • Docker container
  • Environment Variables
  • Docker Compose
  • ioc2rpz™ on AWS
  • Certificate Setup
  • Building from Source
  • ioc2rpz™ management
    • via DNS
    • via REST
  • Monitoring & Health Checks
  • Troubleshooting
  • Configuration file
  • Predefined configuration values
  • How the AXFR and IXFR caches are updated
  • Hot cache
  • How to try ioc2rpz™
  • Some free threat intelligence feeds
  • Further Documentation
  • References
  • Support / Supporters
  • Contact us
  • License

Short summary

ioc2rpz™: The DNS Security Solution - ioc2rpz™ is a powerful DNS server that transforms threat indicators into actionable Response Policy Zone (RPZ) feeds. It automates the update process, ensuring your network is protected against the latest threats, including malicious domains and IP addresses. By converting IOC feeds into RPZs, ioc2rpz™ acts as a crucial link between threat intelligence and DNS security, compatible with RPZ-supporting DNS servers like ISC Bind or PowerDNS.

Overview

DNS is the control plane of the Internet. Usually DNS is used for good but:

  • It can be used to track users locations and their behaviour;
  • Malware uses DNS to command and control, exfiltrate data or redirect traffic;
  • According with 2016 Cisco annual security report, 91.3% of malware use DNS;
  • Advertisements companies usually use separate and obscure domains to show ads;
  • Free DNS services (e.g. 1.1.1.1, 8.8.8.8, 9.9.9.9 etc) can help you to address some concerns but you can not define your own protection settings or ad filters.

ISC Bind is a de facto a standard of a nameserver. With introduction of Response Policy Zones in the ISC BIND 9.8 it is became a simple task to monitor and contain malware on DNS layer. RPZ is supported on PowerDNS recursor 4.0.0 and later releases. Knot DNS is also partially supports RPZ.

In comparing with traditional network protection solutions a DNS server can handle millions of indicators without performance impact but there were no automated and efficient way to maintain response policy zones on primary DNS servers.

Usually indicators of compromise are distributed in plain text but in different formats and only a few providers of IOCs make them available via RPZ.

ioc2rpz™ is a custom DNS server which automatically converts indicators (e.g. malicious FQDNs, IPs) from various sources into RPZ feeds and automatically maintains/updates them. The feeds can be distributed to any open source and/or commercial DNS servers which support RPZ, e.g. ISC Bind, PowerDNS. You can run your own DNS server with RPZ filtering on a router, desktop, server and even Raspberry Pi. System memory is the only limitation.

With ioc2rpz™ you can define your own feeds, actions and prevent undesired communications.

ioc2rpz™ is a place where threat intelligence meets DNS

ioc2rpz™ transforms IOC feeds into response policy zones (RPZ). You can mix feeds to generate a single RPZ or multiple RPZs. Trusted domains and IPs can be whitelisted. ioc2rpz™ supports expiration of indicators and accordingly rebuilds zones.
Alt ioc2rpz™ The current release supports: local files, files/requests via http/https/ftp and shell scripts to access other resource types. You can use any file format if you can write a REGEX to extract indicators and indicators are separated by newline or/and return carriage chars (/n, /r, /r/n).

Architecture Overview

ioc2rpz is built on Erlang/OTP with a supervision tree that ensures fault tolerance and automatic recovery. See docs/architecture.md for full details.

ioc2rpz_app (application)
└── ioc2rpz_sup (supervisor)
    ├── ioc2rpz_db_sup     — ETS table heir process
    ├── ioc2rpz_tcp_sup    — TCP listener pool (5 workers)
    ├── ioc2rpz_udp_sup    — UDP listener
    ├── ioc2rpz_tls_sup    — TLS/DoT listener pool (5 workers) [if cert configured]
    └── ioc2rpz_rest_sup   — Cowboy HTTPS (REST API + DoH) [if cert configured]

Key modules:

ModuleResponsibility
ioc2rpz.erlTCP/TLS DNS worker — accept, parse, validate, respond
ioc2rpz_udp.erlUDP DNS listener — SOA queries
ioc2rpz_conn.erlIOC source fetching (HTTP/HTTPS/file/shell)
ioc2rpz_db.erlETS-based zone and packet cache
ioc2rpz_sup.erlMain supervisor, configuration loading, zone scheduling
ioc2rpz_rest.erlREST management API (Cowboy)
ioc2rpz_doh.erlDNS-over-HTTPS handler

How to use ioc2rpz™

You can use ioc2rpz™ with any DNS server which supports Response Policy Zones e.g. recent versions of ISC BIND, PowerDNS and any commertial DNS server based on these products (e.g. Infoblox, Blue Cat, Efficient IP). A sample bind's configuration file (named.conf) is provided in the cfg folder.

ioc2rpz™ web interface

ioc2rpz.gui is a Management Web interface which is developed as a separate project. It is not required to run ioc2rpz™.

Protocol Support

ioc2rpz™ listens on multiple transport protocols. All transports share the same query processing pipeline: rate limiting, TSIG validation, zone lookup, and response generation. See docs/protocols.md for full protocol documentation.

Port Summary

PortProtocolServiceCondition
53UDPDNS queries (SOA only)Always
53TCPDNS queries, AXFR/IXFR zone transfers, managementAlways
853TCP+TLSDoT — same as TCP but encryptedRequires cert config
443/8443TCP+TLSDoH (/dns-query) and REST APIRequires cert config

UDP (Port 53)

Download Tool