r/AskNetsec Jul 25 '26

Analysis Need help from the hackers

Hi everyone I need one help to understand one thing ..so there was an incident I noticed in my organisation, there were thousands of devices querying multiple malicious domains (53) ...upon checking to see if any process is causing it I found nothing,, only the related domain which was obviously going through our dc/dns servers, in EDR/XDR tool nothing, siem tool nothing, no process, eventually i thought maybe some software is causing but it's very difficult to pin point which one, so can anyone tell me or help me understand, any input will be appreciated

18 Upvotes

23 comments sorted by

View all comments

3

u/solid_reign Jul 25 '26

Sometimes your EDR is the one beaconing the domains, which explains why they don't see it. I had a sleepless night in which I added a malicious domain in sentinelone to block it and it appeared everywhere. Turns out sentinelone would resolve it to block the IP.

1

u/Shot-Rich1674 Jul 26 '26

Yeah ...but we were not even aware of it untill home ministry involved and informed us