DNS Channel (dns)
- Default Mode:
"block" - Target: Core
node:dnsanddns.promisesresolution APIs.
dns channel intercepts hostname resolution queries to prevent exfiltration through domain lookups and DNS tunneling.
Intercepted APIs
envtrap wraps both callback-style and Promise-style methods:
dns.lookupdns.resolve,dns.resolve4,dns.resolve6dns.resolveCname,dns.resolveMx,dns.resolveTxt,dns.resolveSrv- All
dns.promises.*equivalents
Detection Capabilities
Direct Secret In Hostname
Checks if the requested hostname contains an active secret value ( characters). If found, the lookup is blocked before the OS resolver is queried.
Shannon Entropy Tunneling
Splits hostnames into individual subdomain labels and computes their Shannon entropy. Subdomains with length and entropy trigger tunneling warnings.
Cloud Provider Allowlist
Recognizes standard cloud infrastructure suffixes (
*.amazonaws.com, *.cloudfront.net, *.azure.com, *.azurewebsites.net, *.mongodb.net, *.googleapis.com, *.google.com) to prevent false-positive tunneling alerts.FQDN Normalization
Automatically normalizes fully qualified domain names by stripping trailing dots (e.g.,
api.stripe.com. -> api.stripe.com) prior to evaluation.Enforcement Modes
- block (Default)
- warn
- off
Throws a synchronous The query never reaches external DNS nameservers.
Error:Configuration Example
envtrap.json
