---
title: "Infoblox IQ for Threat Defense"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/2448392230/Infoblox%20IQ%20for%20Threat%20Defense"
format: markdown
---
> Macro (toc)

## Overview

Infoblox IQ for Threat Defense is the security-focused part of Infoblox IQ, the agentic AI operations layer for the Infoblox Platform. It investigates DNS security alerts agentically by collecting evidence, analyzing activity, and determining root cause before presenting SOC analysts with confirmed threats, affected users and devices, and recommended remediation actions.

Infoblox IQ for Threat Defense reduces manual investigation of potential threats by performing initial analysis for the customer. It helps customers identify the core issue faster by narrowing the information in each insight. AI-assisted analysis reviews and correlates threat evidence before presenting insights by analyzing detection data, policy data, indicators, assets, and statistics. It also reviews research notes to identify the most relevant information for an insight. This helps analysts understand the core issue faster, reduces the need to manually click through large volumes of supporting data, and surfaces insights that have already undergone preliminary investigation.

Enterprises are inundated with millions of DNS alerts every day on top of countless other security events, far more than a small team of analysts can triage, driving alert fatigue and causing missed actions. Infoblox IQ for Threat Defense delivers a prioritized list of insights, enabling analysts to focus on what matters most   that matters most. It automatically correlates related events and links the relevant indicators, assets, and users to provide immediate who/what/when context in one place, so analysts do not have to search for information across multiple vendor logs. With clear, actionable context from the start, teams move faster, close tickets with confidence, and spend more time reducing risk instead of chasing noise. Infoblox IQ for Threat Defense processes thousands of alerts into prioritized findings that analysts can review, query with natural language, and act on within minutes instead of hours. 

> ℹ️ **Disclaimer**: Infoblox IQ uses AI to generate insights, recommendations, responses, and related outputs. These are for informational purposes only, may contain errors, and users should independently validate them before acting.

## What Infoblox IQ for Threat Defense Provides

### IQ for Threat Defense DNS Monitoring

Infoblox Threat Defense provides protective DNS. Infoblox IQ for Threat Defense strengthens this protection with actionable intelligence and visibility into potential threats.

IQ for Threat Defense monitors DNS activity for phishing, malware, intrusion attempts, and other suspicious activity, including successful and blocked activity, across millions to billions of logs daily. It enriches these logs with threat intelligence, device details, user context, and behavioral patterns. AI-driven risk correlation then identifies activity that warrants investigation, helping security operations center (SOC) teams prioritize potential threats and reduce noise.

A blocked domain does not necessarily indicate that a threat has been contained. An endpoint may already be compromised, or a user may belong to a high-risk segment based on previous behavior. IQ for Threat Defense evaluates DNS activity alongside contextual information to identify potential risks that require further investigation.

When activity warrants investigation, IQ for Threat Defense generates an alert with supporting context to help SOC teams assess the threat and respond before its impact expands. This supports faster containment, reduced threat dwell time, and identification of compromises that might otherwise go undetected.

### Infoblox IQ for Threat Defense Provides Insight also provides the following for each insight:

- Helps analysts understand the core issue faster by identifying the most relevant information associated with an insight.
- Explains why an insight is generated in your environment and comprehensive context on the threat, and thereby its importance
- Lists the indicators, assets, and users** **involved
- Shows connections between attributes - meaning who accessed what through which device and at what time
- Recommended actions to address the incident

By consolidating related alerts, IQ Insights also streamlines the data sent to SIEM systems, minimizing redundant correlations across other security tools. The result is a cleaner, more actionable flow of information and greater operational efficiency across the security ecosystem.

![The workflow used by Infoblox IQ for Threat Defense to manage cybersecurity events and manage data. Infoblox IQ for Threat Defense leverages data, Threat Intel, and artificial intelligence across large volume of security events impacting your network thereby reducing the time it takes to investigate and respond to key incidents.](media://1e27b3e9-3bf9-4765-968e-0cf2bc322351)

### The Differences Between Infoblox IQ for Threat Defense Insights Compared to Prior Insights 

Infoblox IQ for Threat Defense insights offer the following improvements and enhancements compared to prior insights:

- Workflow is streamlined so analysts can easily understand the context and act on an IQ insight.
- IQ insights are granular, so the context can be brought out better.
- IQ insights addresses the issue where events are constantly updating, resulting in the analyst unable to permanently resolve an insight. IQ insights are generated based on what was observed at a specific point in time. For information on Insight generation frequency, see *[Insight Types](https://infoblox-docs.atlassian.net/wiki/spaces/~5f0f5ad9502ce1001d1bd220/pages/2409988353)**.*
- Each IQ insight has new status (beyond just Open and Close) to manage the life cycle of the insight.

## <span style="color: #000000">The Infoblox IQ for Threat Defense Dashboard</span>

The *Infoblox IQ for Threat Defense* security dashboard provides a centralized view of all detected security insights within the Infoblox Threat Defense platform, enabling analysts to assess, triage, and track threats based on severity, threat class, activity trends, investigation activity, affected entities, and individual insight details across monitored assets and users.

<span style="color: #000000">Infoblox IQ for Threat Defense can be accessed from </span>**IQ** > **AI Actions** > **Threat Defense** <span style="color: #000000">in the Infoblox Portal.</span>

### Insights Inventory

Infoblox IQ for Threat Defense maintains an inventory list of insights generated based on activities observed in your environment. For details about inventory workflow, see *[Insights Inventory](https://docs.infoblox.com/space/BloxOneThreatDefense/1793851454/Insights+Inventory)*.  

![The Infoblox IQ for Threat Defense security dashboard. ](media://e804636e-4489-4271-a373-f50523bfae2c)

**Insight Grouping**

Each Insight group is anchored to its topmost Insight, with the remaining Insights primarily representing repeated activity within the same context. Expand a group to view its individual Insights.

On Grouping of Insights - We need to update the IQ-TD documentation also, with a word on grouping and that it anchors on the top-most insights within that, as its primarily repeats within that group and update the screenshot, expanding a grouped insight

## Data Analyzed

Infoblox IQ for Threat Defense analyzes multiple sources of insight-related evidence, including:

| **Evidence Type** | **Description** |
| --- | --- |
| **Detection data** | Security detection information associated with the insight. |
| **Policy data** | Policy-related context that may help explain why the activity was detected or categorized. |
| **Indicators** | Threat indicators associated with the insight. |
| **Assets** | Affected or related assets involved in the observed activity. |
| **Statistics** | Supporting metrics and counts that help summarize the scope or frequency of the activity. |
| **Research notes** | Threat research context used to help explain the meaning or severity of the insight. |

## > Macro (anchor)

Infoblox IQ for Threat Defense Status Workflow

![The IQ Insight Life Cycle flow chart.](media://e0315cbc-0faf-41fa-a901-bea157406e92)

The status of Infoblox IQ for Threat Defense insights is used to manage the Insight life cycle. Insight status is per tenant level and not at per user level. The table describes the different possible statuses

| **IQ Insight State** | **Description** |
| --- | --- |
| **Needs Review** | Indicates that the insight requires additional analyst review before it can be assigned, investigated, or resolved. Use this state when more context, validation, or supporting evidence is needed to determine the appropriate next step. |
| **In Progress** | An Insight has been assigned and is under investigation (assigned responsibility). |
| **Accepted Risk** | Indicates that the insight represents known or expected activity that the organization has chosen to accept without further remediation. Use this state when the activity is understood, documented, and approved as an acceptable business or operational risk. |
| **False Positive** | Indicates that the insight has been reviewed and determined not to represent a valid threat or security concern. Use this state when the observed activity is benign, expected, or incorrectly classified as suspicious. |
| **Resolved** | An investigated Insight that’s resolved. |

* Insights expire after 30 days of creation.

## Infoblox IQ Insight Prioritization

IQ Insight’s prioritization is based on these factors:

1. Number of Assets involved in the insight: Numerical value: 0-3, with each insight assigned a score based on its severity.
2. Threat & Confidence level of the indicators involved in the insight: Numerical value: 0-3
3. State of the Indicator involved - Block & Allowed (Not Blocked): Numerical value: 0-1

## The Time Saved Metric Formula

The Time Saved metric helps users understand the estimated investigation efficiency gained by using Infoblox IQ Insight for Threat Defense. The metric compares the time a human analyst would typically spend reviewing insight-related evidence with the time required when AI-assisted analysis is used. It uses weighted values for events, indicators, and assets to estimate manual investigation time, agent-assisted investigation time, and the resulting time saved. This provides a consistent way to show how AI analysis can reduce investigation effort across insight dashboards.

For additional information on Infoblox IQ for Threat Defense, see the following:

> Macro (children)





** **