Select . You can filter the threat logs based on the specific
type of
Advanced DNS Security domain category, for example
threat_category.value = 'adns-hijacking', whereby
the variable
adns-hijacking indicates DNS queries that
have been categorized as a malicious DNS hijacking attempt by Advanced
DNS Security. The following
Advanced DNS Security threat categories
available in the logs:
Advanced DNS Security Categories
- DNS Hijacking—adns-hijacking
DNS
Hijacking domains have a threat ID of (UTID:
109,004,100).
- DNS
Misconfiguration—adns-dnsmisconfig
DNS
Misconfiguration domains have three threats IDs, which
correspond to three variants of DNS misconfiguration domains
types: dnsmisconfig_zone (UTID: 109,004,200),
dnsmisconfig_zone_dangling (UTID: 109,004,201), and
dnsmisconfig_claimable_nx (UTID: 109,004,202). You can
constrain the search by cross-referencing a Threat-ID value
that corresponds to a specific DNS misconfiguration domain
type. For example, threat_category.value =
'adns-dnsmisconfig' and Threat ID =
109004200, whereby 109004200 indicates the
Threat ID of a DNS misconfiguration domain that does not
route traffic to an active domain due to a DNS server
configuration issue.
DNS Categories analyzed using Advanced DNS Security enhanced response
analysis.
- DNS —adns-benign
- Malware Domains —adns-malware
- Command and Control Domains—adns-c2
- Phishing Domains—adns-phishing
- Dynamic DNS Hosted
Domains—adns-ddns
- Newly Registered
Domains—adns-new-domain
- Grayware Domains—adns-grayware
- Parked Domains—adns-parked
- Proxy Avoidance and
Anonymizers—adns-proxy
- Ad Tracking Domains—adns-adtracking
If the DNS query does not complete within the specified timeout
period for Advanced DNS Security, the DNS Security
categorization will be used, when possible. In those instances,
the legacy notation for the category is used, for example,
instead of adns-malware, it will be categorized
as dns-malware, indicating that the DNS
Security categorization value was used.
Select
Log Viewer. You can filter the threat
logs based on the specific type of
Advanced DNS Security domain
category, for example
threat_category.value =
'adns-hijacking', whereby the variable
adns-hijacking indicates DNS queries that have been
categorized as a malicious DNS hijacking attempt by Advanced DNS
Security. The following
Advanced DNS Security threat categories
available in the logs:
Advanced DNS Security Categories
- DNS Hijacking—adns-hijacking
DNS
Hijacking domains have a threat ID of (UTID:
109,004,100).
- DNS
Misconfiguration—adns-dnsmisconfig
DNS
Misconfiguration domains have three threats IDs, which
correspond to three variants of DNS misconfiguration domains
types: dnsmisconfig_zone (UTID: 109,004,200),
dnsmisconfig_zone_dangling (UTID: 109,004,201), and
dnsmisconfig_claimable_nx (UTID: 109,004,202). You can
constrain the search by cross-referencing a Threat-ID value
that corresponds to a specific DNS misconfiguration domain
type. For example, threat_category.value =
'adns-dnsmisconfig' and Threat ID =
109004200, whereby 109004200 indicates the
Threat ID of a DNS misconfiguration domain that does not
route traffic to an active domain due to a DNS server
configuration issue.
DNS Categories analyzed using Advanced DNS Security enhanced response
analysis.
- DNS —adns-benign
- Malware Domains —adns-malware
- Command and Control Domains—adns-c2
- Phishing Domains—adns-phishing
- Dynamic DNS Hosted
Domains—adns-ddns
- Newly Registered
Domains—adns-new-domain
- Grayware Domains—adns-grayware
- Parked Domains—adns-parked
- Proxy Avoidance and
Anonymizers—adns-proxy
- Ad Tracking Domains—adns-adtracking
If the DNS query does not complete within the specified timeout
period for Advanced DNS Security, the DNS Security
categorization will be used, when possible. In those instances,
the legacy notation for the category is used, for example,
instead of adns-malware, it will be categorized
as dns-malware, indicating that the DNS
Security categorization value was used.
Select a log entry to view the details of the DNS query.
The DNS
Category is displayed under the
General pane of the detailed log view. In
addition, you can see other aspects if the threat, including the origin
URL, the specific threat type, and associated characteristics.
(Optional) Retrieve a list of misconfigured domains and hijacked
domains detected by the
Advanced DNS Security service. The misconfigured domains
are based on the public-facing parent domain entries added to
DNS
Zone Misconfigurations. This is available as a request through
AI Canvas.