- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-02-2023 08:30 PM
Hi Community,
Hope fellows can provide some insights. I have received a suspected DGA alert from my MSSP and upon validating with XDR, it shows Network Services is making such queries. As the domain is my internal domain with gibberish sub-domain, I'm fairly confident this is not a positive DGA incident. What might cause such behavior?
02-07-2023 02:33 AM
Hi Joseph,
Looks like fast flux not DGA but if you dont have so many queries, this might be one of OS binary or service. (might not ofcourse)
I know chrome in some conditions are the root cause of the fast flux but with out doing deep dive analyses on the system, hard to imagine something.
02-07-2023 02:33 AM
Hi Joseph,
Looks like fast flux not DGA but if you dont have so many queries, this might be one of OS binary or service. (might not ofcourse)
I know chrome in some conditions are the root cause of the fast flux but with out doing deep dive analyses on the system, hard to imagine something.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!