<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: what is the difference between Botnet report and DNS Sinkholing? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-difference-between-botnet-report-and-dns-sinkholing/m-p/98003#M44083</link>
    <description>&lt;P&gt;The Botnet Report is an additional source of information for an administrator where the firewall makes a summary of 'suspicious' traffic that did not necessarily get blocked but could be an indication of a dormant infection by adding up all the parts&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dns sinkhole is an interception method that injects spoofed replies in a DNS lookup so the client gets a false IP address to a domain name and when it tries to connect, the session is 'sinkholed'&lt;/P&gt;
&lt;P&gt;This prevents (potentially infected) clients from reaching a malicious host and also makes the source more visible, in case the dns query is routed through an internal DNS server&lt;/P&gt;</description>
    <pubDate>Fri, 15 Jul 2016 09:01:56 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-07-15T09:01:56Z</dc:date>
    <item>
      <title>what is the difference between Botnet report and DNS Sinkholing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-difference-between-botnet-report-and-dns-sinkholing/m-p/97644#M44063</link>
      <description>&lt;P&gt;HI All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what is the difference between Botnet report and DNS Sinkholing? we can see the botnet reports to identify the infected machine by identifing the connection requests to the malicius URL repetedly, please help me to understand this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Guru&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 09:43:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-difference-between-botnet-report-and-dns-sinkholing/m-p/97644#M44063</guid>
      <dc:creator>Gururaj</dc:creator>
      <dc:date>2016-07-14T09:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: what is the difference between Botnet report and DNS Sinkholing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-difference-between-botnet-report-and-dns-sinkholing/m-p/97688#M44066</link>
      <description>&lt;P&gt;My understanding of sinkholing is that when it's active you are actively inspecting the traffic and then setting the DNS record to send it to another device, often times stopping the traffic all together. The botnet report is simply telling you that the PA has identified the devices going to the malicious links but doesn't actively take steps to block it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 12:53:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-difference-between-botnet-report-and-dns-sinkholing/m-p/97688#M44066</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-07-14T12:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: what is the difference between Botnet report and DNS Sinkholing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-difference-between-botnet-report-and-dns-sinkholing/m-p/98003#M44083</link>
      <description>&lt;P&gt;The Botnet Report is an additional source of information for an administrator where the firewall makes a summary of 'suspicious' traffic that did not necessarily get blocked but could be an indication of a dormant infection by adding up all the parts&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dns sinkhole is an interception method that injects spoofed replies in a DNS lookup so the client gets a false IP address to a domain name and when it tries to connect, the session is 'sinkholed'&lt;/P&gt;
&lt;P&gt;This prevents (potentially infected) clients from reaching a malicious host and also makes the source more visible, in case the dns query is routed through an internal DNS server&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 09:01:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-difference-between-botnet-report-and-dns-sinkholing/m-p/98003#M44083</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-07-15T09:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: what is the difference between Botnet report and DNS Sinkholing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-difference-between-botnet-report-and-dns-sinkholing/m-p/98501#M44141</link>
      <description>&lt;P&gt;As Reaper notes, the sinkhole is a great add on to the bot net report. &amp;nbsp;With the report we frequently have to do some detective work with the logs can cross references to get the actual source address of the infected machines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With a sinkhole you not only block the traffic, but you get a solid and direct host address to go and clean up.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2016 23:50:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-is-the-difference-between-botnet-report-and-dns-sinkholing/m-p/98501#M44141</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2016-07-19T23:50:28Z</dc:date>
    </item>
  </channel>
</rss>

