Skip to content

DNS Resolvers

Evidence: DNS Resolvers
Description: Collect DNS Resolvers
Category: Network
Platform: macos
Short Name: dnsr
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

This collector gathers DNS resolver configuration from macOS. This data is essential for understanding name resolution paths, detecting DNS-based attacks, and investigating connectivity issues.

This collector gathers structured data about dns resolvers.

FieldDescriptionExample
AddressTypeIndexAddress Type Index123
AddressTypeAddress TypeExample value
AddressAddressExample value
NetMaskNet MaskExample value
OptionsOptions123

This collector queries the dns_resolvers table via osquery and records results into the dns_resolvers table.

This evidence is crucial for forensic investigations as it reveals DNS servers, netmask/search configuration, and options that can indicate misconfigurations or malicious redirection.