Skip to content

Commit

Permalink
Merge pull request #33 from kayavila/patch-1
Browse files Browse the repository at this point in the history
Update FAQ.md
  • Loading branch information
romainw authored Jan 7, 2025
2 parents 449a157 + 628c1a0 commit 375e16e
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions FAQ.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ _A: Yes, pDNSSOC will combine the intel from several MISP instances and allow fo

Q: An external team has their own "private" MISP instance and pDNSSOC deployment. How could we benefit from it without breaching TLP or privacy?

_A: pDNSSOC can send incoming DNS data to be reprocessed by another pDNSSOC instance operated by a different team.
_A: pDNSSOC can send incoming DNS data to be reprocessed by another pDNSSOC instance operated by a different team._

**Privacy**: DNS collection can be configured to hide the client IP and use either the DNS server IP or the pDNSSOC instance IP instead. As a result, the client IP or originating DNS server is not exposed to the external team.

Expand All @@ -26,4 +26,4 @@ _A: pDNSSOC deployments follow a scale-out approach. Tests showed that a single

Q: Is pDNSSOC aimed at prevention?

_A: No. A primary objective of pDNSSOC is to improve incident response capabilities. With sufficient pDNSSOC coverage, CSIRTs should simply add malicious IPs/Domains in MISP to obtain a near-realtime view of the ongoing attack against their community. Connecting pDNSSOC instances as well as MISP instances together allows a community to response together to security incidents._
_A: No. A primary objective of pDNSSOC is to improve incident response capabilities. With sufficient pDNSSOC coverage, CSIRTs should simply add malicious IPs/Domains in MISP to obtain a near-realtime view of the ongoing attack against their community. Connecting pDNSSOC instances as well as MISP instances together allows a community to response together to security incidents._

0 comments on commit 375e16e

Please sign in to comment.