r/cybersecurity 🔐 Cybersecurity 👁 0

Sinkholed domain

If I have Cortex XDR + palo alto NGFW and an internal DNS server, and a user queries a malicious domain that gets sinkholed In XDR, should the alert show the DNS server as source and I have to pivot to find the endpoint

📄

This source provides headlines only. Use the button below to read the complete article on the original site.

📰 Read the original article on r/cybersecurity

Originally published by r/cybersecurity. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.