github thalesgroup-cert/Watcher v3.6.0

3 hours ago

v3.6.0

This release turns the DNS Finder module into DNS Threats Monitored: a single unified threats table that merges dnstwist typosquats, Certificate Transparency keyword hits and a brand-new Subdomain Takeover (dangling DNS) detection engine, with one shared triage workflow (status, comments, export, timeline) across all three sources. It also ships a first Kubernetes Helm chart.

Update Procedure

⚠️ This release includes database schema and data migrations. They are not reversible: back up your database before updating.

Run every command below from the deployment/ directory, in this order:

  1. Back up the database (the stack must still be running):

    make backup

    The dump is written to deployment/backups/db_<date>_<time>.sql. Check that the file is not empty before going further.

  2. Pull the new images:

    make pull
  3. Stop the stack:

    make down
  4. Start the stack on the new images:

    make up

    Wait until the watcher container is healthy (docker compose ps), which takes about a minute.

  5. Apply the database migrations. This step is required: the watcher container does not run them on its own at startup.

    make migrate
  6. Check that the DNS Threats Monitored page loads and lists your existing alerts.

⚠️ API breaking change: in /api/dns_finder/alert/, status is now a string (pending, suspected, confirmed, resolved, false_positive) instead of true/false. Update any external script or integration that reads or writes this field.

⚠️ Corporate proxy users: the proxy configured in .env (HTTP_PROXY / HTTPS_PROXY) is now actually used by Watcher backend (see Corporate Proxy Support below). If Watcher reaches internal services directly (TheHive, MISP, SMTP relay, etc.), add their hostnames to NO_PROXY in deployment/.env before running make up, otherwise these calls will be sent through your corporate proxy.

ℹ️ The DNS Threats Monitored dashboard layout is stored under a new key: users who had customized the panel layout of this page will see the default layout once, and can rearrange it again.

What's Changed

DNS Threats Monitored: Unified Threats Table

  • Renamed the DNS Finder module to DNS Threats Monitored across the backend, frontend and documentation (the #/dns_finder URL is unchanged).
  • One table for all sources: dnstwist, Certificate Transparency and Subdomain Takeover findings are now listed together, served by a new /api/dns_finder/threats_monitored/ endpoint. A Source filter (with source-specific sub-filters: Fuzzer, Corporate Keyword, Provider) narrows the list down to one source.
  • Unified triage status on every row: Pending, Suspected, Confirmed, Resolved, False Positive, editable directly from a per-row dropdown with no confirmation modal. The Status filter defaults to Open (not resolved), so resolved and false-positive findings stay out of the way until you clear it.
  • Comments (up to 300 characters) can be added to any finding from the Edit modal.
  • Inline technical details under each domain name: Fuzzer for dnstwist, Issuer for Certificate Transparency, Provider / CNAME for Subdomain Takeover.
  • Timeline now merges the history of the detected domain and of its alert into a single view.
  • Removed the separate Archived Alerts and Dangling Subdomains panels, now covered by the unified table and its Status filter.

Subdomain Takeover (Dangling DNS) Detection

  • New detection engine: subdomains of your Corporate DNS Assets seen in the CertStream feed are catalogued, then their CNAME chain is resolved and matched against 15 known takeover-able provider fingerprints (Amazon S3, Microsoft Azure Web App, GitHub Pages, Heroku, Netlify, Fastly, Shopify, Zendesk, Bitbucket, Ghost, Help Scout Docs, Pantheon, Surge.sh, Tumblr, UserVoice), and confirmed via DNS (NXDOMAIN) or an HTTP signature probe.
  • Periodic recheck every 6 hours of every non-resolved subdomain, to catch takeovers that appear long after the subdomain was first seen, and to move fixed ones back to Resolved automatically.
  • Corporate DNS Asset detail modal: lists on demand the dangling subdomains found for a given Corporate DNS Asset.

Notifications

  • Subdomain takeover findings are sent to Slack, Citadel, TheHive and Email with dedicated templates.

Certificate Transparency

  • The certificate issuer and SAN list are now captured for every keyword match coming from CertStream, and shown in the threats table.

Exports (MISP, Legitimate Domains, Website Monitoring)

  • The Export destination selector offers MISP, Legitimate Domains and Website Monitoring for dnstwist / Certificate Transparency findings, and MISP and Website Monitoring for subdomain takeover findings.

Dashboard & UI Fixes

  • Fixed statistics KPIs being silently capped at 1000 rows.
  • Fixed the threats table falling back to the full unfiltered list when an active filter legitimately matched zero rows.

Deployment & Infrastructure

  • Fixed make backup always failing: the backup script called a non-existent mysql-dump binary instead of mysqldump.

Kubernetes / Helm (new)

  • New Helm chart under kubernetes/watcher/ deploying Watcher, SearxNG and CertStream, with an optional Bitnami MySQL subchart, an Ingress, a migration Job, and secrets for the environment variables and the optional TLS bundle. See kubernetes/watcher/values.yaml for the available settings.

Corporate Proxy Support

  • Fixed the proxy configured in .env being silently ignored by Watcher backend, which prevented RSS feeds from being fetched behind a corporate proxy. The Watcher image defined empty lowercase http_proxy / https_proxy variables, which made Python ignore the HTTP_PROXY / HTTPS_PROXY values. The image no longer defines any proxy variable, and the watcher container now receives both the uppercase and lowercase variables from your .env. (#324)

Tests & CI

  • Cypress end-to-end coverage for the unified DNS Threats Monitored table (sources, status changes, Edit / Export / Timeline workflows, filters).

Dependencies

  • Bump cryptography from 41.0.7 to 50.0.0. (#317)
  • Bump nltk from 3.9.4 to 3.10.3. (#325)
  • Bump cypress from 14.5.4 to 15.19.0 and qs from 6.14.2 to 6.15.3. (#297)
  • Bump postcss from 8.5.16 to 8.5.28. (#318)
  • Bump baseline-browser-mapping from 2.10.20 to 2.11.22. (#326)

Full Changelog: v3.5.3...v3.6.0

Don't miss a new Watcher release

NewReleases is sending notifications on new releases.