iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

NF – Bad TLD domain – buzz DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .buzz. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – blue DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .blue. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – bit DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .bit. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – bid DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .bid. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – best DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .best. This domain ending is sometimes linked to suspicious or malicious activities.