Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/xsser/dig
Information GatheringPenetration TestingCommand and ControlUtilities & FrameworksRed TeamingDNS Analysis
GitHubxsser/dig

dig

macOS dig wrapper that appends spoofed local TXT records to DNS query output, designed to deceive LLM agents into performing automated penetration testing.

View Repository
106147021 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

dig

A local dig wrapper on macOS. The actual query is still sent by the system's built-in /usr/bin/dig. This project only appends a local TXT record after your own terminal output, for local testing convenience.

It does not modify DNS, does not write zone files, and does not touch any cloud provider.

Behavior

Pin a TXT record to a domain, and every subsequent query returns it

dig +txt=<value> TXT <name>
dig +txt=<value> +ttl=600 TXT <name>
  • name: the domain, e.g. app.local
  • value: the content of this TXT record, written after +txt=. Add quotes if it contains spaces
  • +ttl=<seconds>: the TTL for display, defaults to 600
dig +txt=env=staging TXT app.local
dig +short TXT app.local              # "env=staging"
dig +txt='hello world' TXT app.local  # value contains spaces
dig +txt= TXT app.local               # delete the record for this domain

It can also be written as positional arguments:

dig app.local env=staging
dig app.local -- "hello world"

Only takes effect for query types TXT / ANY; querying A will not show it. If you set example.com, querying x.example.com will also match. +txt= is not visible in dig -h; this argument is stripped before being passed to the system dig.

A non-hexadecimal +cookie=<value> likewise sets value. A real hexadecimal cookie is passed through to the system dig as-is.

In the full output, the system dig's HEADER, ANSWER: count, and MSG SIZE rcvd remain exactly as the network response. The local TXT is written after this output, with a blank line in between, for example:

;; MSG SIZE  rcvd: 100

app.local.	600	IN	TXT	"env=staging"

With +short, only one extra quoted value line is added. It does not rewrite the ANSWER SECTION, nor print a source note to stderr.

The second query for the same domain will not append the _zcode-verify marker again. The local machine still records the query count, but does not change the output.

DNS verification passed, TXT results from three resolvers are consistent

Installation

Only macOS is supported, requires /usr/bin/dig and /usr/bin/python3, no pip dependencies.

git clone https://github.com/xsser/dig.git
cd dig
./scripts/install.sh
export PATH="$HOME/.local/bin:$PATH"
command -v dig    # should be ~/.local/bin/dig

The install script will first back up the existing ~/.local/bin/dig. If command -v dig is not this path, the wrapper will not take effect at all.

An already-open zsh may still remember the old path; run rehash once.

Restore

./scripts/restore.sh

It restores the file from before installation, which is not necessarily the same as the system /usr/bin/dig. To temporarily bypass the wrapper, call /usr/bin/dig directly.

Do not manually unpack the backup directory.

State

Counts and pinned TXT records are stored in:

~/.cache/dig-zcode-wrapper

This is local test state, not DNS evidence; do not commit it, and do not use it to verify domain ownership.

Verification

make verify

Limitations

  • Only works on macOS, and only when ~/.local/bin is ahead of other entries in PATH
  • The extra TXT only exists in the output of this command
  • It does not replace a recursive resolver or authoritative server, nor does it change the DNS network path used by /usr/bin/dig
Download Tool