{"repo":"giantswarm/coredns-warnlist-plugin","free":true,"listed":false,"github":"https://github.com/giantswarm/coredns-warnlist-plugin","clone":"git clone https://github.com/giantswarm/coredns-warnlist-plugin.git","description":"CoreDNS plugin exposing Prometheus metrics for malicious or prohibited requests","language":"Go","stars":11,"topics":["go","coredns","security","prometheus","intrusion-detection"],"license":"Apache-2.0","category":"analytics","readme_excerpt":"warnlist plugin Description CoreDNS plugin which periodically updates a cache of domains, and exposes metrics and logs when a listed domain is requested. It does not block the request. This plugin is intended to facilitate low-noise alerting based on DNS requests for known malicious domains. This plugin was previously referred to as malicious-domains . This project is under development and has not been tested for heavy production workloads. Usage We host a coredns image including this plugin at quay.io/giantswarm/coredns-warnlist-plugin . While we will try to keep this up to date on a best-effort basis, this is not an official image and may become behind or out of sync with the official image. Alternatively, you can build an image yourself from the upstream codebase using the instructions in the Compilation section below. Arguments The warnlist plugin takes the following arguments: - the source type for the warnlist: either url or file - the path to the source: either a url or file path - the format of the file to expect: either hostfile or text (see below) - the reload period: an optional Go Duration after which time (+/- 30% jitter) the warnlist will be regenerated - whether or not to match subdomains: true (default) or false (see Subdomains) \\ when automatically reloading from a URL, please be friendly to the service hosting the file. In your Corefile, the plugin options follow the format: Sample Corefile configuration snippet (URL): Sample Corefile configuration snippet (","default_branch":null,"files":null,"tree":[],"storefront":"/r/giantswarm","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/giantswarm/coredns-warnlist-plugin/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}