See the threat. Govern the response.
Block known malicious destinations at DNS resolution. Detect the novel threats and covert behaviours that reputation feeds alone cannot see.
What DNS Shield looks for
Eleven policies cover malicious destinations, suspicious domain behaviour and covert DNS channels. Each detection carries a MITRE ATT&CK technique, showing what the attacker was trying to do, not only what was observed.
- 01
Algorithmic domain generation
Generated names used to rendezvous with control infrastructure, caught before a blocklist can be updated.
- 02
Brand impersonation
Look-alike, homoglyph and typo-squat domains impersonating the organization’s brands and its partners’.
- 03
Threat-intelligence enforcement
Resolution of domains already attributed to threat actors or active campaigns.
- 04
Geographic anomaly
Domains resolving to unexpected geographies, weighing against proxy abuse and hijacked hosting.
- 05
Evasive infrastructure
Rapidly rotating address-to-domain mappings used to evade takedown.
- 06
Reconnaissance
Zone-transfer and bulk-enumeration requests that expose internal DNS structure.
- 07
Behavioral anomaly
Bursts of non-existent-domain responses, characteristic of a host cycling names to find a live controller.
- 08
Traffic anomaly
Abnormal query volume to one destination, exposing beaconing, tunneling and data staging.
- 09
Control-channel beaconing
The regular timing cadence of a beacon calling home, including low-volume beacons.
- 10
Exfiltration and tunneling
Oversized or encoded payloads in TXT and other record types, moving data out or tunneling a channel.
- 11
Integrity and tampering
Mismatched or manipulated answers, indicating cache poisoning or spoofing.
How hidden threats reveal themselves
Three representative policies show how DNS Shield detects threats that a static blocklist can miss.
Algorithmic domain generation
Malware can generate hundreds of pseudo-random domains until one reaches its command infrastructure. DNS Shield scores the statistical signature of the name itself using a lexical model trained on character-level patterns, independent of whether the domain has been seen before.
Control-channel beaconing
A control channel running over DNS can reveal itself through the regular timing of its calls home. DNS Shield analyses query cadence, including slow, low-volume beacons that threshold-based tools can miss, even on devices that cannot run an agent.
Exfiltration and tunneling
Attackers can hide encoded payloads inside TXT and other DNS record types. DNS Shield examines content, length and randomness to distinguish suspicious transfer patterns from legitimate use, then reports the activity to TDIR as a detection in its own right.
From multiple signals to one governed verdict
A false refusal can disrupt a business-critical domain, so DNS Shield does not rely on one signal. It evaluates several independent detection sources and combines their weighted contributions into one risk score. No single signal can produce a confirmed-malicious verdict on its own.
- Resolved
Benign
Resolved normally and recorded for traceability and behavioral baselining.
- Alert only
Suspicious
Recorded and alerted for review, with no enforcement unless tenant policy escalates it.
- Refused or sinkholed
Likely
Refused or sinkholed per tenant policy, and surfaced for analyst confirmation.
- Refused
Confirmed
Resolution is refused, an alert fires, and the detection is sent to TDIR with its decision context.
The confidence band and tenant policy determine whether a query is resolved, alerted, refused or sinkholed. Confirmed verdicts are refused by default; lower-confidence activity remains governed by tenant policy and analyst review.
What the security team gains
DNS Shield turns DNS activity into an earlier control point and clearer investigation context.
- Before connection
Stop known threats earlier
Known malicious destinations can be refused at DNS resolution, before a connection is established.
- Behaviour-led
See beyond reputation feeds
Lexical, timing and traffic analysis reveal novel domains and covert behaviour that static lists may miss.
- Agentless reach
Protect more of the environment
Resolver-level visibility covers devices in scope that cannot run an endpoint agent.
- Decision context
Give analysts the why
TDIR receives the detection with its confidence and attacker-technique context, ready for investigation.
Detection context you can explain
Every detection carries a MITRE ATT&CK technique, confidence band and transaction record. This context helps analysts explain the verdict and can support evidence requirements across NIST CSF, ISO 27001, NIS2, DORA and the EU Cyber Resilience Act. It supports governance and reporting; it does not make an organisation compliant.

Every event
- Technique tag
- Confidence band
- Transaction record
Maps to MITRE ATT&CK
EVIDENCE FOR
- NIST CSF
- ISO 27001
- NIS2
- DORA
- EU Cyber Resilience Act
See a DNS verdict become an incident
See how DNS activity becomes a scored verdict, a governed action and a detection an analyst can investigate.
Connect with the team
Book a demo
For service providers
Go to the MSSP platform