logo

Farsight's DNSDB Time Fencing: A Post-Attack "Time Machine"

ID: 4e44e15d-4c6a-5565-9280-d10ef1017330

STIX ID: report--4e44e15d-4c6a-5565-9280-d10ef1017330

Feed Name: DomainTools

Threat Score
20/100

Date Published: 2026-03-27

Date Updated: 2026-04-27

Author: domaintools.com

...
...

This post explains DNSDB’s “time fencing” capabilities and how to use the dnsdbq CLI to limit DNS historical queries to specific time ranges (loose vs. complete/strict modes, absolute and relative times). It provides examples and a short case study where Fox-IT experienced unauthorized registry-level DNS changes that briefly pointed nameservers to attacker-controlled cloud names (a potential MitM), but Farsight’s DNSDB data showed limited exposure and the incident was rapidly remediated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.