What is Triple DNS?
Triple DNS is TripleCyber's identity-aware DNS security layer. Traditional DNS resolves names to addresses with no awareness of who is making the request or whether the destination is trustworthy. Triple DNS changes this by applying TripleEnablement trust classification to every DNS query, enabling policy-driven resolution and real-time threat blocking.
How It Fits into TripleSOC
Triple DNS generates high-value telemetry that flows directly into the TripleSOC indexer. Every DNS query is logged with:
- The trust zone of the requesting entity (Anonymous, Verified, or Secure)
- The risk classification of the target domain
- Whether the query was allowed, redirected, or blocked
This DNS telemetry enriches TripleSOC's threat detection. When an endpoint queries a known command-and-control domain, TripleSOC correlates that event with the endpoint's trust zone and ZTRS risk score to generate a high-fidelity alert.
Key Capabilities
- Trust-aware resolution — DNS responses vary based on the requester's trust zone
- Real-time domain blocking — malicious and suspicious domains are blocked at the DNS layer before any connection is made
- DNS tunneling detection — identifies data exfiltration attempts hidden in DNS traffic
- Policy-driven filtering — Triple ABAC policies control which domains are accessible based on user and device attributes
- Full query logging — every DNS transaction is indexed in TripleSOC for investigation and compliance
How It Works with Other Components
Triple DNS enforces access policies defined in Triple ABAC and consumes risk intelligence from ZTRS. When a device's risk score crosses a threshold, Triple DNS can automatically restrict resolution to essential domains only. Triple PKI certificates validate the identity of DNS infrastructure components, ensuring the DNS layer itself is not compromised.