Domain match

Prev Next

Domain-match alerts show when an endpoint has requested Domain Name System (DNS) to resolve a known malicious hostname. This alert means that the DNS was resolved. It does not indicate that any malicious payloads have been downloaded or that exploitative content has been accessed. Domain matches are not blocked because they are just name resolutions. There is no target IP address in this type of match. The alert has the exact time that the Network Security appliance picked up the DNS traffic.

By itself, this type of alert is for informational purposes only. If a high volume of domain matches is occurring, the endpoint might be compromised and needs to be cleaned.