System Overview

End Device
Phone / Laptop
Client Agent
DNS-over-HTTPS
DNS Resolver
Knot Resolver + HA
Threat Intel
CSIRT.CZ + ML
Admin Portal
Dashboard & Policies

Core Components

DNS Resolver

Built on Knot Resolver with high availability and DNSSEC support. Deploys using Anycast technology as on-premise or virtual appliance. Responds only to queries from authorized networks.

Open Source HA DNSSEC Anycast

Administrative Portal

Detailed traffic overview, security policy configuration, event logging and analysis. Display and filter DNS queries, manage connected device inventory.

Open Source Dashboard Policies

Agent for End Devices

Available for Android, iOS, and Windows. Automatically configures DNS resolver and provides optional DNS-over-HTTPS encryption. Protects users outside the organization network.

Open Source Android iOS Windows

Threat Intelligence Database

Combines commercial and public threat databases with Czech legislation-compliant domain blacklists. Regularly updated feeds from CSIRT.CZ and other sources for malicious domain detection.

CSIRT.CZ ML Analysis Auto-updated

Deployment Modes

Flexible deployment options to match your organization's security posture.

Blocking Mode

Detected malicious domains are blocked immediately, preventing access to threats in real time.

Audit Mode

Logging only with no interventions. Perfect for evaluating threats before enabling enforcement.

Custom Policies

Administrator-defined protection levels by threat type. Fine-tune blocking rules to your organization's needs.

System Integration

DNS Patrol connects to your existing security monitoring tools with alert and notification support.

CSIRT.CZ
National threat intelligence feed
Security Monitoring
SIEM and SOC integration
Alerts & Notifications
Real-time incident alerts
DNS Log Export
Analysis and long-term monitoring
Custom Blocklists
Organizational block/allow lists
Knot Resolver
High-performance DNS backbone