Hello everyone!
I found the UNWIND tool very interesting.
I have particularly devoted some time to the issue of DNS traffic hijacking.
Unfortunately this has been a common practice in some ISPs.
They do this either by DST-NAT or by Well-Know Open Resolvers hijacking (like 8.8.8.8 1.1.1.1 9.9.9.9 4.4.2.2).
I have been thinking for some time about scalable mechanisms for identifying and reporting ISPs that have this bad practice.
I wondered that adapting UNWIND to do this kind of verification would not be difficult.
What do you think?