DNS Shield · Detection

See the threat. Govern the response.

Block known malicious destinations at DNS resolution. Detect the novel threats and covert behaviours that reputation feeds alone cannot see.

What DNS Shield looks for

Eleven policies cover malicious destinations, suspicious domain behaviour and covert DNS channels. Each detection carries a MITRE ATT&CK technique, showing what the attacker was trying to do, not only what was observed.

  • 01

    Algorithmic domain generation

    Generated names used to rendezvous with control infrastructure, caught before a blocklist can be updated.

  • 02

    Brand impersonation

    Look-alike, homoglyph and typo-squat domains impersonating the organization’s brands and its partners’.

  • 03

    Threat-intelligence enforcement

    Resolution of domains already attributed to threat actors or active campaigns.

  • 04

    Geographic anomaly

    Domains resolving to unexpected geographies, weighing against proxy abuse and hijacked hosting.

  • 05

    Evasive infrastructure

    Rapidly rotating address-to-domain mappings used to evade takedown.

  • 06

    Reconnaissance

    Zone-transfer and bulk-enumeration requests that expose internal DNS structure.

  • 07

    Behavioral anomaly

    Bursts of non-existent-domain responses, characteristic of a host cycling names to find a live controller.

  • 08

    Traffic anomaly

    Abnormal query volume to one destination, exposing beaconing, tunneling and data staging.

  • 09

    Control-channel beaconing

    The regular timing cadence of a beacon calling home, including low-volume beacons.

  • 10

    Exfiltration and tunneling

    Oversized or encoded payloads in TXT and other record types, moving data out or tunneling a channel.

  • 11

    Integrity and tampering

    Mismatched or manipulated answers, indicating cache poisoning or spoofing.

How hidden threats reveal themselves

Three representative policies show how DNS Shield detects threats that a static blocklist can miss.

  1. Algorithmic domain generation

    Malware can generate hundreds of pseudo-random domains until one reaches its command infrastructure. DNS Shield scores the statistical signature of the name itself using a lexical model trained on character-level patterns, independent of whether the domain has been seen before.

  2. Control-channel beaconing

    A control channel running over DNS can reveal itself through the regular timing of its calls home. DNS Shield analyses query cadence, including slow, low-volume beacons that threshold-based tools can miss, even on devices that cannot run an agent.

  3. Exfiltration and tunneling

    Attackers can hide encoded payloads inside TXT and other DNS record types. DNS Shield examines content, length and randomness to distinguish suspicious transfer patterns from legitimate use, then reports the activity to TDIR as a detection in its own right.

From multiple signals to one governed verdict

A false refusal can disrupt a business-critical domain, so DNS Shield does not rely on one signal. It evaluates several independent detection sources and combines their weighted contributions into one risk score. No single signal can produce a confirmed-malicious verdict on its own.

Several independent detection sources are weighted and combined into one risk score. The score falls into one of four confidence bands: Benign, Suspicious, Likely and Confirmed. Only Confirmed refuses by default.
  • Resolved

    Benign

    Resolved normally and recorded for traceability and behavioral baselining.

  • Alert only

    Suspicious

    Recorded and alerted for review, with no enforcement unless tenant policy escalates it.

  • Refused or sinkholed

    Likely

    Refused or sinkholed per tenant policy, and surfaced for analyst confirmation.

  • Refused

    Confirmed

    Resolution is refused, an alert fires, and the detection is sent to TDIR with its decision context.

The confidence band and tenant policy determine whether a query is resolved, alerted, refused or sinkholed. Confirmed verdicts are refused by default; lower-confidence activity remains governed by tenant policy and analyst review.

What the security team gains

DNS Shield turns DNS activity into an earlier control point and clearer investigation context.

  • Before connection

    Stop known threats earlier

    Known malicious destinations can be refused at DNS resolution, before a connection is established.

  • Behaviour-led

    See beyond reputation feeds

    Lexical, timing and traffic analysis reveal novel domains and covert behaviour that static lists may miss.

  • Agentless reach

    Protect more of the environment

    Resolver-level visibility covers devices in scope that cannot run an endpoint agent.

  • Decision context

    Give analysts the why

    TDIR receives the detection with its confidence and attacker-technique context, ready for investigation.

Detection context you can explain

Every detection carries a MITRE ATT&CK technique, confidence band and transaction record. This context helps analysts explain the verdict and can support evidence requirements across NIST CSF, ISO 27001, NIS2, DORA and the EU Cyber Resilience Act. It supports governance and reporting; it does not make an organisation compliant.

Detection context mapping from every event to the ClearSkies iISOC platform

Every event

  • Technique tag
  • Confidence band
  • Transaction record

Maps to MITRE ATT&CK

EVIDENCE FOR

  • NIST CSF
  • ISO 27001
  • NIS2
  • DORA
  • EU Cyber Resilience Act

See a DNS verdict become an incident

See how DNS activity becomes a scored verdict, a governed action and a detection an analyst can investigate.