iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

NF – Bad TLD domain – company DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .company. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – club DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .club. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – click DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .click. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – cf DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .cf. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – camera DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .camera. This domain ending is sometimes linked to suspicious or malicious activities.