Focus
Strata Cloud Manager

Insights: DNS Security

Table of Contents

Insights: DNS Security

The DNS Security Operator Dashboard provides a central view of DNS threat activity with immediate, actionable insights for security teams.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
Each of these licenses include access to Strata Cloud Manager:
The other licenses and prerequisites needed for visibility are:
  • A role that has permission to view the dashboard
  • DNS Security or Advanced DNS Security
  • Strata Logging Service
The features and capabilities available to you in Strata Cloud Manager depend on which license(s) you are using.
  • Click Strata Cloud ManagerInsightsSecurityDNS Security to get started.
This image shows a partial view of the dashboard. Additional widgets may be available, and dashboard content is subject to change.

Dashboard Scope and Capabilities

The DNS Security Operator Dashboard is a subscription-specific view that delivers a centralized hub for DNS threat activity, offering immediate and actionable insights. Interactive widgets surface critical efficacy metrics—such as top malicious domains, C2 domain traffic, and users and devices accessing malicious domains—providing an intuitive starting point for deeper drill-down analysis. By utilizing contextual data on users, devices, and policies, security teams can detect, investigate, and remediate DNS-based threats more efficiently than ever before.
Flexible Data Filtering: Customize the dashboard time range (from the last 15 minutes up to 45 days, or define a custom range) and apply general filters to isolate specific datasets.
Interactive Widgets: Interact directly with individual widgets to filter data, reorder columns, zoom, view raw data, export as CSV, and toggle legends and labels.
Key Visibility Metrics
The dashboard provides granular visibility into the following areas:
  • Overview—Total DNS query count (malicious versus benign) and total DNS queries over time, providing a snapshot of DNS security posture across your network.
  • Domain and user attribution—Top malicious domains by category and query count, and top users and devices accessing malicious domains, helping identify which domains are generating the most malicious traffic and which users are most exposed.
  • Geography and categories—Top destination countries with malicious domains, breakdown of malicious DNS threats by category, and breakdown of malicious DNS categories by policy action to support reporting and investigative workflows.
  • Threat details—Top C2 domains with traffic counts, domain hijacking activity (Advanced DNS Security only), top DNS resolvers by request count and resolver IP, and DNS misconfigurations such as cloakable NX entries or expired domains (Advanced DNS Security only).
Operational Use Cases
Leverage the dashboard data to drive the following investigative and operational initiatives:
  • Detect covert channels encoded in DNS queries—Threats often encode C2 commands directly into DNS queries to bypass standard firewalls. Monitor domain traffic volume and query counts to expose anomalous patterns. A domain with unusually high query volume may indicate a compromised host beaconing to a C2 server, while multiple domains with elevated counts may indicate a broader campaign.
  • Confirm compromise by correlating users and domains—Cross-reference high-volume malicious DNS traffic with specific users. If a single user account appears repeatedly across multiple malicious domains, this confirms that a compromised host is communicating with attacker infrastructure despite evasion techniques such as domain generation algorithms (DGAs) or DNS tunneling.
  • Stop data exfiltration and protocol abuse—Identify and block specific domains used for command-and-control communication. Detect domains that have been redirected to attacker-controlled infrastructure (Advanced DNS Security only). Together, these neutralize the threat's ability to receive instructions or exfiltrate data, protecting against the final stage of the attack lifecycle.
  • Identify and remediate DNS misconfigurations—Detect configuration issues such as typosquatting domains or expired DNS entries that could be exploited by attackers or indicate accidental exposure (Advanced DNS Security only).
  • Demonstrate ROI to leadership—Provide high-level summaries of total queries versus total malicious queries along with category breakdowns to demonstrate the value and effectiveness of your DNS security investment in executive reporting.