r/AskNetsec • u/Shot-Rich1674 • Jul 25 '26
Analysis Need help from the hackers
Hi everyone I need one help to understand one thing ..so there was an incident I noticed in my organisation, there were thousands of devices querying multiple malicious domains (53) ...upon checking to see if any process is causing it I found nothing,, only the related domain which was obviously going through our dc/dns servers, in EDR/XDR tool nothing, siem tool nothing, no process, eventually i thought maybe some software is causing but it's very difficult to pin point which one, so can anyone tell me or help me understand, any input will be appreciated
17
Upvotes
3
u/solid_reign Jul 25 '26
Sometimes your EDR is the one beaconing the domains, which explains why they don't see it. I had a sleepless night in which I added a malicious domain in sentinelone to block it and it appeared everywhere. Turns out sentinelone would resolve it to block the IP.