ShenDNS
The layer every outbound connection starts with
DNS is the first step in nearly every outbound connection an attacker needs — command-and-control check-ins, exfiltration channels, phishing infrastructure. ShenDNS controls that layer, blocking malicious resolution before a connection is ever established.
Because it sits at the same chokepoint, it also reveals what your own environment is reaching out to — the shadow IT and policy violations that represent some of the highest-risk insider vectors in an enterprise. Blocking at the point of resolution, rather than alerting after the connection, is what makes it a preemptive cybersecurity control rather than a monitoring one.
Preemptive threat prevention
| Blocks | Why it matters |
|---|---|
| Command-and-control channels | Cuts C2 communication for malware, ransomware, and APT tooling at the resolution step, before a session exists |
| Phishing and credential harvesting | Blocks phishing domains and credential-harvesting infrastructure targeting your staff |
| Newly registered domains | Detects domains registered for active campaigns before they appear in commercial threat feeds |
| CATIS IOFA domain indicators | Consumes predictive domain intelligence from CATIS in real time, ahead of commercial threat-feed publication |
Operational visibility and shadow IT
The same vantage point that blocks attacker infrastructure also surfaces what staff and unmanaged systems are actually using.
- Unauthorised remote access tools and personal screen-sharing software creating unmonitored access paths into your environment
- Free VPN clients routing corporate traffic through unknown third-party infrastructure
- Unauthorised cloud storage and file sharing carrying sensitive data out of the environment
- Personal AI services receiving internal documents, source code, or customer data from staff
Visibility without surveilling your staff
Employee-level DNS data is the obvious objection to any product in this category, so the control comes first: ShenDNS supports configurable anonymisation of employee-level DNS data. You retain organisation-level visibility — which categories, which risks, which policy gaps — without building a per-person browsing record.
That is what makes the capability deployable under GDPR and comparable regimes, and under works-council agreements where per-employee monitoring would not be permitted. Configure it to the standard your jurisdiction and your staff agreements require.
What you receive
- Blocked-domain summary with category breakdown for the period
- Shadow IT findings, with recommended policy actions
- Newly observed campaign infrastructure relevant to your environment
Where ShenDNS sits in the platform
ShenDNS is one half of the Deny pillar. Where NanoFirewall enforces prevention on the device and at the network edge, ShenDNS enforces it at the DNS layer — both consuming Indicators of Future Attacks from CATIS automatically, without waiting for a human to approve a rule.
Its blocking decisions and DNS telemetry flow into ASPEN, where they correlate with deception, endpoint, and conventional log data in a single investigation.