Interpreting the DNS Threat Filter report

Options
InCash
InCash Posts: 3  Freshman Member
First Comment Fourth Anniversary

Please help me understand what the following report means and how I can fix the problem. The client IP address in the report is the address of our internal domain controller DNS server. It is set as the primary DNS address on the client computers. Both the endpoints and the servers have endpoint-side antivirus. Where do I start? Should I look for malicious applications on internal computers?

All Replies

  • Zyxel_James
    Zyxel_James Posts: 788  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers

    You can check the DNS Threat Filter information in SecuReporter.
    Please go to SecuReporter > Analysis > Security Indicator > DNS Threat Filter, scroll down to DNS Threat Filter Hit Detail, and click the by Source IP tab, it display the Hits counters by Source IP, and if you click on the IP address, the page will display the complete information of the Source IP that encounter DNS Threat Filter.

    image.png image.png image.png
  • InCash
    InCash Posts: 3  Freshman Member
    First Comment Fourth Anniversary

    Dear James, so I can really see the problem in more detail, but I still don't know what to do to fix it. I already knew from which IP address and where the requests were going, but there is no malicious application on the source computer. I have checked with several business endpoint protection software. Where do I look for the source of the problem?

    kép.png