
ioc2rpz is a place where threat intelligence meets DNS.
ioc2rpz™: The DNS Security Solution - ioc2rpz™ is a powerful DNS server that transforms threat indicators into actionable Response Policy Zone (RPZ) feeds. It automates the update process, ensuring your network is protected against the latest threats, including malicious domains and IP addresses. By converting IOC feeds into RPZs, ioc2rpz™ acts as a crucial link between threat intelligence and DNS security, compatible with RPZ-supporting DNS servers like ISC Bind or PowerDNS.
DNS is the control plane of the Internet. Usually DNS is used for good but:

ISC Bind is a de facto a standard of a nameserver. With introduction of Response Policy Zones in the ISC BIND 9.8 it is became a simple task to monitor and contain malware on DNS layer. RPZ is supported on PowerDNS recursor 4.0.0 and later releases. Knot DNS is also partially supports RPZ.
In comparing with traditional network protection solutions a DNS server can handle millions of indicators without performance impact but there were no automated and efficient way to maintain response policy zones on primary DNS servers.
Usually indicators of compromise are distributed in plain text but in different formats and only a few providers of IOCs make them available via RPZ.
ioc2rpz™ is a custom DNS server which automatically converts indicators (e.g. malicious FQDNs, IPs) from various sources into RPZ feeds and automatically maintains/updates them. The feeds can be distributed to any open source and/or commercial DNS servers which support RPZ, e.g. ISC Bind, PowerDNS. You can run your own DNS server with RPZ filtering on a router, desktop, server and even Raspberry Pi. System memory is the only limitation.
With ioc2rpz™ you can define your own feeds, actions and prevent undesired communications.
ioc2rpz™ transforms IOC feeds into response policy zones (RPZ). You can mix feeds to generate a single RPZ or multiple RPZs. Trusted domains and IPs can be whitelisted. ioc2rpz™ supports expiration of indicators and accordingly rebuilds zones.
The current release supports: local files, files/requests via http/https/ftp and shell scripts to access other resource types. You can use any file format if you can write a REGEX to extract indicators and indicators are separated by newline or/and return carriage chars (/n, /r, /r/n).
ioc2rpz is built on Erlang/OTP with a supervision tree that ensures fault tolerance and automatic recovery. See docs/architecture.md for full details.
ioc2rpz_app (application)
└── ioc2rpz_sup (supervisor)
├── ioc2rpz_db_sup — ETS table heir process
├── ioc2rpz_tcp_sup — TCP listener pool (5 workers)
├── ioc2rpz_udp_sup — UDP listener
├── ioc2rpz_tls_sup — TLS/DoT listener pool (5 workers) [if cert configured]
└── ioc2rpz_rest_sup — Cowboy HTTPS (REST API + DoH) [if cert configured]
Key modules:
| Module | Responsibility |
|---|---|
ioc2rpz.erl | TCP/TLS DNS worker — accept, parse, validate, respond |
ioc2rpz_udp.erl | UDP DNS listener — SOA queries |
ioc2rpz_conn.erl | IOC source fetching (HTTP/HTTPS/file/shell) |
ioc2rpz_db.erl | ETS-based zone and packet cache |
ioc2rpz_sup.erl | Main supervisor, configuration loading, zone scheduling |
ioc2rpz_rest.erl | REST management API (Cowboy) |
ioc2rpz_doh.erl | DNS-over-HTTPS handler |
You can use ioc2rpz™ with any DNS server which supports Response Policy Zones e.g. recent versions of ISC BIND, PowerDNS and any commertial DNS server based on these products (e.g. Infoblox, Blue Cat, Efficient IP). A sample bind's configuration file (named.conf) is provided in the cfg folder.
ioc2rpz.gui is a Management Web interface which is developed as a separate project. It is not required to run ioc2rpz™.
ioc2rpz™ listens on multiple transport protocols. All transports share the same query processing pipeline: rate limiting, TSIG validation, zone lookup, and response generation. See docs/protocols.md for full protocol documentation.
| Port | Protocol | Service | Condition |
|---|---|---|---|
| 53 | UDP | DNS queries (SOA only) | Always |
| 53 | TCP | DNS queries, AXFR/IXFR zone transfers, management | Always |
| 853 | TCP+TLS | DoT — same as TCP but encrypted | Requires cert config |
| 443/8443 | TCP+TLS | DoH (/dns-query) and REST API | Requires cert config |