Interpreting the DNS Threat Filter report

InCash
InCash Posts: 2  Freshman Member
Fourth Anniversary

Please help me understand what the following report means and how I can fix the problem. The client IP address in the report is the address of our internal domain controller DNS server. It is set as the primary DNS address on the client computers. Both the endpoints and the servers have endpoint-side antivirus. Where do I start? Should I look for malicious applications on internal computers?

All Replies

  • Zyxel_James
    Zyxel_James Posts: 745  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers

    You can check the DNS Threat Filter information in SecuReporter.
    Please go to SecuReporter > Analysis > Security Indicator > DNS Threat Filter, scroll down to DNS Threat Filter Hit Detail, and click the by Source IP tab, it display the Hits counters by Source IP, and if you click on the IP address, the page will display the complete information of the Source IP that encounter DNS Threat Filter.

    image.png image.png image.png