Create a Post
Showing results for 
Search instead for 
Did you mean: 

Some DNS request not block by AV blade

I have disable DNS trap feature because I have no use internal DNS.

When I verify the log I see some request not block in the same protection name.

Please advice.

0 Kudos
1 Reply

Keep in mind Anti-Bot is primarily a post-infection blade.
If a machine is looking up a potentially sketchy hostname via DNS, the machine could already be infected.
By default, we do classification in the background.
In the cases where there was a Prevent, the DNS name was in the gateway's local cache.
In the case where it was Detect, it wasn't immediately in the cache.

More discussion about this topic here:


Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events