The @firstdotorg DNS Abuse SIG has now released v1.3 of the DNS Abuse Techniques Matrix, after the last version published back in 2023. We've been working hard on consistency, clarity, and overall polish to create a foundation for further work, and I am SO proud to be part of this publication. It's awesome to see it being used more and more. It was weird (but so cool!) the first time I was chatting with an AI and it answered with a reference to our own work!
Download the latest version here: https://www.first.org/global/sigs/dns/DNS-Abuse-Techniques-Matrix_v1.3.pdf
The DNS Abuse Techniques Matrix lists 21 different types of DNS Abuse, and 15 different stakeholder groups, marking which of those groups are able to help when it comes to detection, prevention, and mitigation of each abuse type. It's a starting point for anyone dealing with DNS Abuse to know who's going to be able to help move forward. Or who should have the capability to help, at least.
As a companion to this, we've also published a set of advice to stakeholders:
https://www.first.org/global/sigs/dns/stakeholder-advice/
These are more specific articles which include definitions, examples, resources, and of course the advice itself on how to deal with each type of DNS Abuse - so once you get talking, again a starting point to help deal with incidents.
If you're not familiar with the SIG -- or, Special Interest Group, because not everyone knows every acronym! -- then a bit of background: FIRST, the Forum of Incident Response and Security Teams, provides a platform and support for various groups covering all sorts of security-related topics. Our overall mission is to aid incident responders and security teams with the language and essential knowledge to combat DNS Abuse. There's more to it, but we welcome applications from outside FIRST (subject to approval from SIG members) - so check us out:
https://www.first.org/global/sigs/dns/
In addition to this, we've started tracking changes more properly on the site, which we really should have been doing from the start:
https://www.first.org/global/sigs/dns/CHANGES
A ton of people have worked on this over the years, but I'd like to give a shoutout to my co-chair Vinzenz Vogel for all the help, especially lately.
There is, of course, always more work to do, and we have a long TODO list. Most of that past this version is going to be meatier updates and improvements, and at some point we'll publish v2.0 which will include "breaking changes" like new categories etc. Join us if you'd like to be part of this effort.