iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

NF – Bad TLD domain – date DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .date. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – cricket DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .cricket. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – country DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .country. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – consulting DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .consulting. This domain ending is sometimes linked to suspicious or malicious activities.

NF – Bad TLD domain – computer DNS query – Check domains

This alert is triggered when a DNS query from the internal network attempts to resolve a domain ending in .computer. This domain ending is sometimes linked to suspicious or malicious activities.