https://catalogartifact.azureedge.net/publicartifacts/katabarwalabs.dangling-dns-9856a652-c559-499a-a588-6667368db8bb/image3_logo216.png
Dangling DNS Sentinel — Subdomain Takeover Monitor
بواسطة Katabarwa Labs Inc.
Just a moment, logging you in...
Daily subdomain-takeover scan of your Azure DNS — catch dangling CNAMEs before attackers claim them.
A subdomain takeover happens when a DNS record still points at a cloud endpoint you no longer own — an attacker claims that endpoint and now serves content from your domain. Azure ships a one-off detection script but nothing that runs continuously. Dangling DNS Sentinel closes that gap.
WHAT IT DOES
Dangling DNS Sentinel deploys into your own Azure subscription as a managed application. Every day it enumerates the CNAME records across your Azure DNS zones, resolves each one from inside your tenant, and flags any record that points at an Azure service endpoint whose backing resource no longer exists — the takeover-able ones — posting an alert to Microsoft Teams with remediation steps.
WHO IT IS FOR
Security teams, platform engineers, and anyone responsible for a domain with more DNS records than they can audit by hand.
WHY IT IS SAFE
There is no vendor backend. It runs on a consumption Function inside your subscription, reads DNS configuration with a read-only managed identity you control, resolves names from within your own network, and sends alerts only to the Teams webhook you configure. Delete the managed application and every trace is gone.
SETUP
Deploy from the marketplace, paste a Teams webhook URL, and run one script to grant the managed identity read-only Reader access. The first scan runs the next morning.
لمحة سريعة
https://catalogartifact.azureedge.net/publicartifacts/katabarwalabs.dangling-dns-9856a652-c559-499a-a588-6667368db8bb/image2_shot1.png