DESCRIPTION LAST UPDATED: 2023-12-06
DEFAULT SEVERITY LEVEL: INFO
This report lists DNS queries seen from recursive DNS servers for sinkholed domains. Please note that the IP listed are not the same as the actual source IP of the client that is making the query and hence are likely not infected hosts. This report therefore is to be used primarily to support investigations into a threat, and not as a source of direct identification of infected hosts.
Severity levels are described here.
Filename: event4_sinkhole_dns