<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I identify which PC made a suspicious DNS query? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-identify-which-pc-made-a-suspicious-dns-query/m-p/71809#M40939</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/21249"&gt;@SOC_CSG﻿&lt;/a&gt;&amp;nbsp; You can create filter the traffic log for the DNS queries directed towards the Sinkhole address. You may create a report using traffic logs as well :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/threat-prevention/identify-infected-hosts.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/threat-prevention/identify-infected-hosts.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2016 02:26:50 GMT</pubDate>
    <dc:creator>syadav</dc:creator>
    <dc:date>2016-01-29T02:26:50Z</dc:date>
    <item>
      <title>How do I identify which PC made a suspicious DNS query?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-identify-which-pc-made-a-suspicious-dns-query/m-p/71780#M40933</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have setup the Anti-Spyware Profile in our firewall and I have a lot of threat logs of type spyware suspicious DNS &amp;nbsp;queries from a domain controller machine and this is cleansed.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="line-height: 20px;"&gt;Monitor &amp;gt; Logs &amp;gt; Threat list&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2239i122FA0F529456BD7/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="sinkhole.jpg" title="sinkhole.jpg" /&gt;&lt;/P&gt;
&lt;P&gt;As you can see I have configured the sinkhole method. But I woluld like to know how could I identify which PC are making this suspicious DNS queries?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Diego&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 16:18:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-identify-which-pc-made-a-suspicious-dns-query/m-p/71780#M40933</guid>
      <dc:creator>SOC_CSG</dc:creator>
      <dc:date>2016-01-28T16:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: How do I identify which PC made a suspicious DNS query?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-identify-which-pc-made-a-suspicious-dns-query/m-p/71786#M40936</link>
      <description>&lt;P&gt;You have to look for traffic towards the sinkhole IP in your traffic log, if it's configured as an IP outside the PC LAN.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 17:21:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-identify-which-pc-made-a-suspicious-dns-query/m-p/71786#M40936</guid>
      <dc:creator>gtomte</dc:creator>
      <dc:date>2016-01-28T17:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do I identify which PC made a suspicious DNS query?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-identify-which-pc-made-a-suspicious-dns-query/m-p/71809#M40939</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/21249"&gt;@SOC_CSG﻿&lt;/a&gt;&amp;nbsp; You can create filter the traffic log for the DNS queries directed towards the Sinkhole address. You may create a report using traffic logs as well :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/threat-prevention/identify-infected-hosts.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/threat-prevention/identify-infected-hosts.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2016 02:26:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-identify-which-pc-made-a-suspicious-dns-query/m-p/71809#M40939</guid>
      <dc:creator>syadav</dc:creator>
      <dc:date>2016-01-29T02:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: How do I identify which PC made a suspicious DNS query?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-identify-which-pc-made-a-suspicious-dns-query/m-p/71814#M40940</link>
      <description>&lt;P&gt;HI ,&lt;/P&gt;
&lt;P&gt;I think that you should configure fake ip address on sinkhole ipv4 field. That fake ip addressin not used inside of the network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2246i374CA9FE96EA2B1B/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Capture.PNG" title="Capture.PNG" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then you need to have security rule that block all access to fake ip address .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe it's helpful&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2016 03:19:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-do-i-identify-which-pc-made-a-suspicious-dns-query/m-p/71814#M40940</guid>
      <dc:creator>gombodorj</dc:creator>
      <dc:date>2016-01-29T03:19:52Z</dc:date>
    </item>
  </channel>
</rss>

