DNS poisoning detection for Windows`
DNS Watchdog is a PowerShell script for Windows that monitors local DNS traffic to detect signs of DNS poisoning or spoofing. It uses the built-in Windows packet capture tool pktmon to capture DNS packets and analyzes them for conflicting DNS responses, unexpected DNS server replies, unmatched DNS answers, and ARP spoofing indicators. The tool is heuristic and may produce false positives, but repeated alerts can indicate real attacks. It requires Windows 10 (1809+) or later and runs without third-party dependencies.
AI Analysis
Technical Summary
DNS Watchdog for Windows is a native PowerShell script that leverages pktmon, the built-in Windows packet capture utility, to monitor DNS traffic on a host for indications of DNS poisoning or spoofing. It captures DNS queries and responses at the OS networking stack level, parsing raw pcapng packets to detect conflicting DNS answers to the same query, responses from unconfigured DNS servers, answers without matching queries, and changes in the default gateway's MAC address that may indicate ARP spoofing. The script runs in short capture windows, deduplicates repeated packets, and logs alerts with technical details and plain-language explanations. It requires elevated PowerShell and recent Windows builds supporting pktmon pcapng conversion. Limitations include heuristic detection with potential false positives, gaps between capture windows, and inability to detect poisoning occurring solely within remote resolvers.
Potential Impact
This tool helps detect DNS poisoning attempts on the local machine by identifying conflicting or suspicious DNS responses and ARP spoofing events that could lead to DNS tampering. It does not itself represent a vulnerability or exploit but provides monitoring capability to alert defenders to potential DNS-based attacks targeting the host. Detection can enable timely investigation and response to DNS spoofing threats.
Mitigation Recommendations
This is a detection tool rather than a vulnerability requiring patching. No official patch or fix is applicable. Users should run the script with administrative privileges on supported Windows versions to monitor DNS traffic for poisoning attempts. Because it is heuristic, users should interpret alerts carefully and consider repeated or clustered alerts as more meaningful. No vendor advisory or official remediation applies.
DNS poisoning detection for Windows`
Description
DNS Watchdog is a PowerShell script for Windows that monitors local DNS traffic to detect signs of DNS poisoning or spoofing. It uses the built-in Windows packet capture tool pktmon to capture DNS packets and analyzes them for conflicting DNS responses, unexpected DNS server replies, unmatched DNS answers, and ARP spoofing indicators. The tool is heuristic and may produce false positives, but repeated alerts can indicate real attacks. It requires Windows 10 (1809+) or later and runs without third-party dependencies.
Reddit Discussion
https://github.com/microlaser/dns_watchdog_windows2
Sure it is vibe coded, but it is free and open source and has no dependencies. I have a version that runs on MacOS and Linux too. Uses pcaps to detect DNS poisoning. Everything is native, no Wireshark/tcpdump needed.
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
DNS Watchdog for Windows is a native PowerShell script that leverages pktmon, the built-in Windows packet capture utility, to monitor DNS traffic on a host for indications of DNS poisoning or spoofing. It captures DNS queries and responses at the OS networking stack level, parsing raw pcapng packets to detect conflicting DNS answers to the same query, responses from unconfigured DNS servers, answers without matching queries, and changes in the default gateway's MAC address that may indicate ARP spoofing. The script runs in short capture windows, deduplicates repeated packets, and logs alerts with technical details and plain-language explanations. It requires elevated PowerShell and recent Windows builds supporting pktmon pcapng conversion. Limitations include heuristic detection with potential false positives, gaps between capture windows, and inability to detect poisoning occurring solely within remote resolvers.
Potential Impact
This tool helps detect DNS poisoning attempts on the local machine by identifying conflicting or suspicious DNS responses and ARP spoofing events that could lead to DNS tampering. It does not itself represent a vulnerability or exploit but provides monitoring capability to alert defenders to potential DNS-based attacks targeting the host. Detection can enable timely investigation and response to DNS spoofing threats.
Defensive Guidance
This is a detection tool rather than a vulnerability requiring patching. No official patch or fix is applicable. Users should run the script with administrative privileges on supported Windows versions to monitor DNS traffic for poisoning attempts. Because it is heuristic, users should interpret alerts carefully and consider repeated or clustered alerts as more meaningful. No vendor advisory or official remediation applies.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6abc1dba680226ef683bc130
Added to database: 09/29/2026, 20:21:14 UTC
Last enriched: 09/29/2026, 20:21:18 UTC
Last updated: 09/30/2026, 03:24:28 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.