Jump to content

Recommended Posts

Posted

The Palo Alto is showing me 4 or 5 connections an hour to a known spyware source (api.a-tu-zi.com) but of course as we are domain network all queries are showed as coming from the internal DNS server rather than the requesting internal client, is there any logging on the DNS server that might let me find out which internal client made the request to know where/who/what api.a-tu-zi.com was?

 

LeEdit - it's a 2003 MS server on a DC running built in DNS.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...