Passive DNS

Noun · Security & Infosec

Definitions

  1. A historical record of observed DNS resolutions collected from sensors or providers, used to investigate how domains have mapped to IPs over time. Passive DNS is valuable in threat hunting because malicious infrastructure often changes rapidly, leaving patterns that live DNS queries no longer show.

    In plain English: Historical DNS lookup data used to investigate domains and IP changes over time.

    Example: "Passive DNS linked the phishing domain to the same hosting cluster used by the actor's previous credential-harvesting campaign."

Related Terms