Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • This is great, I was already doing research in that area for my tool. What about a container that writes to the /etc/hosts? It won’t emit DNS queries at all and because of that the connections will show up as bare IPs without domain. That’s a known trick, already exploited (collusion.wiki mentioned here on HN two days ago)

Explore Birbla archives

Dsnitch – Real-time, zero-config Docker egress inspector via eBPF · Birbla