Blog | G5 Cyber Security

Botnet Domain List: Detection & Blocking

TL;DR

This guide shows you how to find lists of domain names used by botnets and block them to protect your network. We’ll cover where to get the lists, how to check them, and ways to use them in firewalls or DNS servers.

1. Finding Botnet Domain Lists

Several sources provide regularly updated lists of known malicious domains associated with botnets. Here are some reliable options:

These lists are often available in formats like TXT, CSV or JSON.

2. Checking the Lists

Before blocking domains, it’s important to verify their legitimacy. False positives can disrupt legitimate services. Here’s how:

3. Blocking Domains in Your Firewall

Most firewalls allow you to block domains based on DNS requests. The exact method varies depending on your firewall vendor.

4. Blocking Domains with DNS Servers

You can configure your DNS server (e.g., Pi-hole, Unbound) to resolve malicious domains to a sinkhole IP address.

5. Automating Updates

Botnet domain lists change frequently, so it’s crucial to automate the update process.

Exit mobile version