Skip to main content
Introducing Polarity Intel Edition: Streamlining Intel Distribution for SecOps
Polarity Intel Edition
Request a Demo

DNS Query

DNS Query utilizes DNS commands on the command like to provide DNS information on IPs or Domains. It performs DNS lookups and displays the answers that are returned from the queried name server(s). The DNS Query integration runs this command automatically for users.

Integrations

DNS Query with Polarity

The Polarity - DNS Query integration allows Polarity users to run varying dig commands right from Polarity instead of having to run the command on a network. This enables users to quickly get a view on what the domain or IP records are. The integration enables users to run multiple different queries.

The Polarity DNS Query integration leverages the NodeJS Native DNS library to issue DNS queries to a specified DNS server. The integration allows you to specify what type of query is run. By default, the integration runs an A record query for domains and a PTR (reverse DNS) query for IP addresses.

Examples

Data Overview

Analysts will be able to quickly understand associated DNS information with IPs and Domains. Enabling quick understanding on the associated information with a domain and IP.

Polarity admins have the ability to specify what data gets returned from a DNS query lookup.

Analysts can look up the following information about an IP and domain:

  • A (IPv4)
  • AAAA IPv6)
  • TXT (Text Annotations)
  • CNAME (Canonical Name Record)
  • NS (Name Server)
  • MX (Mail Exchange)
  • SoA (Start of Authority)
Keep Reading

Built By Polarity

Looking for an
integration not shown?