iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

NF – Bad TLD domain – report DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .report. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – ren DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .ren. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – racing DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .racing. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – pw DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .pw. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – pink DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .pink. This domain ending is sometimes linked to suspicious or malicious activities.