cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

L2 Linker

Hello @JacobYonkman,

 

Before we dive into XQL query/investigation. It's better to understand how's the infrastructure being setup.

Questions:

  1. Is your Domain Controller work as a DNS server
  2. Did the NGFW enable DNS sinkhole?
  3. Do all of your endpoints install with Cortex XDR agent?

Apart from Question 3, the investigation needs to be carry out from NGFW.

Here's an article of DNSSinkhole that might help you identify the source that attempted to access a malicious website.

How DNS Sinkholing Works (paloaltonetworks.com)

AC
Who rated this post