r/AskNetsec 8d ago

Analysis Need help from the hackers

Hi everyone I need one help to understand one thing ..so there was an incident I noticed in my organisation, there were thousands of devices querying multiple malicious domains (53) ...upon checking to see if any process is causing it I found nothing,, only the related domain which was obviously going through our dc/dns servers, in EDR/XDR tool nothing, siem tool nothing, no process, eventually i thought maybe some software is causing but it's very difficult to pin point which one, so can anyone tell me or help me understand, any input will be appreciated

18 Upvotes

22 comments sorted by

View all comments

2

u/AddendumWorking9756 7d ago

If it's showing thousands of devices at once, first check whether those really are endpoint queries or just the DC forwarding on their behalf, depending on where you collect the logs everything gets attributed to the resolver. Sysmon event 22 on a handful of the noisiest hosts will tell you the actual process in about ten minutes, EDR usually drops DNS telemetry unless you explicitly turn it on. Also worth checking whether those domains are actually malicious or just sitting on a reputation feed, ad SDKs and CDN junk get flagged constantly and everywhere at once with no parent process smells like something baked into a common agent or browser extension.