iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

NF – Bad TLD domain – party DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .party. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – mom DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .mom. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – ml DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .ml. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – men DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .men. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – loan DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .loan. This domain ending is sometimes linked to suspicious or malicious activities.