iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

NF – Bad TLD domain – gdn DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .gdn. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – futbol DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .futbol. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – fit DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .fit. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – enterprises DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .enterprises. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – domains DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .domains. This domain ending is sometimes linked to suspicious or malicious activities.