Sign inSign up

cernity/dns-detector

By cernity

Updated 10 days ago

DNS-based detection: NXDOMAIN patterns and tunneling

Image
0

597

cernity/dns-detector repository overview

Cernity — dns-detector

DNS-based detection: NXDOMAIN patterns and tunneling.

Part of Cernity — central network detection & response (NDR) analytics for Suricata sensors. Suricata inspects packets at the edge and ships telemetry; Cernity runs the heavy, stateful, Zeek/RITA-style analysis centrally and emits security findings to your SIEM.

Raw network telemetry is analytics input. Security findings are SIEM input.

This image

cernity/dns-detector — DNS-based detection: NXDOMAIN patterns and tunneling.

Quickstart

See a finding end to end with no live sensor:

docker compose -f deploy/quickstart/docker-compose.yml up
Deploy
  • Single host — Docker Compose (evaluation / small sites)
  • Manual multi-server — Compose across your own hardware, no orchestration
  • Kubernetes — Helm chart with autoscaled detectors

Scales to ~1,000 sensors / ~10 Gbps of edge inspection. Full docs, architecture, and sizing guide: https://github.com/cernity/cernityndr

License

Source-available under the PolyForm Perimeter License 1.0.1 — use it any way you like, except providing it to others as a competing product. "Cernity" is a trademark of the Cernity Project.

Tag summary

Content type

Image

Digest

sha256:247ee0a24

Size

123 MB

Last updated

10 days ago

docker pull cernity/dns-detector