iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

Category: Radiflow

( 189 Alerts)

NF – Bad TLD domain – review DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .review. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – science DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .science. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – space DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .space. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – stream DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .stream. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – tk DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .tk. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – trade DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .trade. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – vacations DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .vacations. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – wang DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .wang. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – work DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .work. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – xin DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .xin. This domain ending is sometimes linked to suspicious or malicious activities.