iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

NF – Bad TLD domain – link DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .link. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – kim DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .kim. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – jetzt DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .jetzt. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – guru DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .guru. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – gq DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .gq. This domain ending is sometimes linked to suspicious or malicious activities.