The DNS Security Operator Dashboard is a subscription-specific view that
delivers a centralized hub for DNS threat activity, offering immediate and
actionable insights. Interactive widgets surface critical efficacy metrics—such
as top malicious domains, C2 domain traffic, and users and devices accessing
malicious domains—providing an intuitive starting point for deeper drill-down
analysis. By utilizing contextual data on users, devices, and policies, security
teams can detect, investigate, and remediate DNS-based threats more efficiently
than ever before.
Flexible Data Filtering: Customize the dashboard time range (from the
last 15 minutes up to 45 days, or define a custom range) and apply general
filters to isolate specific datasets.
Interactive Widgets: Interact directly with individual widgets to filter
data, reorder columns, zoom, view raw data, export as CSV, and toggle legends
and labels.
Key Visibility Metrics
The dashboard provides granular visibility into the following areas:
- Overview—Total DNS query count (malicious versus benign) and
total DNS queries over time, providing a snapshot of DNS security posture
across your network.
- Domain and user attribution—Top malicious domains by category
and query count, and top users and devices accessing malicious domains,
helping identify which domains are generating the most malicious traffic
and which users are most exposed.
- Geography and categories—Top destination countries with
malicious domains, breakdown of malicious DNS threats by category, and
breakdown of malicious DNS categories by policy action to support
reporting and investigative workflows.
- Threat details—Top C2 domains with traffic counts, domain
hijacking activity (Advanced DNS Security only), top DNS resolvers by
request count and resolver IP, and DNS misconfigurations such as
cloakable NX entries or expired domains (Advanced DNS Security
only).
Operational Use Cases
Leverage the dashboard data to drive the following investigative and operational
initiatives:
- Detect covert channels encoded in DNS queries—Threats often
encode C2 commands directly into DNS queries to bypass standard
firewalls. Monitor domain traffic volume and query counts to expose
anomalous patterns. A domain with unusually high query volume may
indicate a compromised host beaconing to a C2 server, while multiple
domains with elevated counts may indicate a broader campaign.
- Confirm compromise by correlating users and domains—Cross-reference
high-volume malicious DNS traffic with specific users. If a single user
account appears repeatedly across multiple malicious domains, this
confirms that a compromised host is communicating with attacker
infrastructure despite evasion techniques such as domain generation
algorithms (DGAs) or DNS tunneling.
- Stop data exfiltration and protocol abuse—Identify and block
specific domains used for command-and-control communication. Detect
domains that have been redirected to attacker-controlled infrastructure
(Advanced DNS Security only). Together, these neutralize the threat's
ability to receive instructions or exfiltrate data, protecting against
the final stage of the attack lifecycle.
- Identify and remediate DNS misconfigurations—Detect configuration
issues such as typosquatting domains or expired DNS entries that could be
exploited by attackers or indicate accidental exposure (Advanced DNS
Security only).
- Demonstrate ROI to leadership—Provide high-level summaries of
total queries versus total malicious queries along with category
breakdowns to demonstrate the value and effectiveness of your DNS
security investment in executive reporting.