---
title: "Executive Summary Report"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35406182/Executive%20Summary%20Report"
format: markdown
---
## Executive Summary Report Overview

The **Executive Summary Report **is a high-level security intelligence deliverable designed to provide organizations with a concise snapshot of DNS-related threat activity and risk posture within their network. Generated regularly (e.g., weekly), the report analyzes DNS telemetry, threat intelligence signals, and behavioral indicators to highlight trends, surface potential risks, and guide proactive security actions.

> ⚠️ **Note: **
> ⚠️ 
> ⚠️ All report data is obtained from your organization's security policy with the exception of lookalike data, which is obtained from your organization's lookalike configuration.

<span style="color: #000000">The Executive Summary Report is available to subscribers of Infoblox Threat Defense Business Cloud and Infoblox Threat Defense Advanced. The Executive Summary Report is not available for Infoblox Threat Defense Essentials or for Infoblox Threat Defense Business On-Premises subscribers.</span>

The purpose of Executive Summary Report is the following: 

- **Provide visibility** into emerging threats and DNS-based activity patterns.
- **Highlight notable security indicators** such as lookalike domains, zero-day activity, DNS tunneling, and known threat actor behavior.
- **Support risk-based decision-making** by surfacing prioritized events and actionable insights.
- **Enable cross-team communication** between security operations, IT, and executive stakeholders by summarizing technical findings in a digestible format.

The Executive Summary Report includes the following information: 

1. **Key Findings and Risk**  
Summarizes notable observations from the reporting period, including early-stage threat infrastructure, impersonation domains, and abnormal behaviors that may indicate elevated risk.
2. **Security Indicator Summary**  
Provides a categorized breakdown of DNS-based security events, such as high-risk queries, malicious domain resolutions, lookalike domain detections, and threat actor sightings.
3. **Critical Event Metrics**  
Highlights counts of malicious or suspicious activity, including unique domains accessed, high-severity queries, and DNS tunneling indicators.
4. **Threat Intelligence Insights**  
Correlates DNS queries with external threat intelligence to detect associations with known campaigns, malware families, and domain generation algorithms.
5. **Recommendations to Mitigate Risk**  
Offers tailored guidance on improving threat prevention, detection, and response, including blocking strategies, monitoring enhancements, and the use of domain mitigation services.
6. **Traffic Volume Statistics**  
Presents total DNS event volume to illustrate the scale of traffic analyzed and the unique vantage point DNS provides for threat visibility.

The Executive Summary Report's intended audience is the following:

- Security Operations Teams (SOC Analysts, Threat Hunters)
- IT and Network Security Administrators
- Risk and Compliance Officers

The **Executive Summary Report** includes the following informational sections:

## Executive Summary: Key Findings and Risk

The **Key Findings and Risk** section provides a high-level overview of notable security observations derived from DNS traffic and threat intelligence analysis. It highlights potential indicators of compromise, suspicious patterns, and activities that may pose reputational, operational, or data-related risks to the organization.

This section is designed to surface meaningful trends, such as the emergence of lookalike domains, activity from known threat actors, signs of DNS-based exfiltration or tunneling, and early-stage threat infrastructure. While not all findings may represent active threats, they serve as important signals for proactive risk mitigation and security posture assessment.

The goal of this section is to help security teams quickly identify areas of concern, prioritize investigative actions, and inform decisions about protective controls and monitoring strategies.

| ### **Executive Summary** | ### **Description** |
| --- | --- |
| Critical Events | The number of malicious events observed. |
| Critical Domains | The number of unique malicious domains (Second-level domain) accessed. |
| Risky Domains | Detected domains that are likely to be used in a future malicious campaign. |
| Data Exfiltration / Tunneling | Detected activity associated with potential data compromise or loss. |
| Lookalike Domains | Domains created by threat actors to impersonate your brand for malicious purposes. |
| Zero-Day DNS | Domains registered and launched within a small window. |
| Recommendations To Mitigate Risk (see section below) | This section provides recommendations on how to mitigate risk. |

### Recommendations to Mitigate Risk 

The **Recommendations to Mitigate Risk** sub-section within the Executive Summary section, provides actionable guidance to help organizations reduce their exposure to the threats and vulnerabilities identified in the report. These recommendations are based on observed patterns and potential risks surfaced through DNS analytics and threat intelligence.

This sub-section outlines strategic and tactical measures that security teams can implement to enhance protection, such as enabling DNS-based threat blocking, monitoring suspicious domain activity, strengthening brand protection, or leveraging advanced detection capabilities. The suggested actions are designed to support a proactive defense posture, improve threat response efficiency, and minimize the likelihood of future compromise.

The guidance presented serves as a bridge between threat visibility and operational response, helping organizations translate insights into measurable risk reduction.

## Security Indicator Summary

The **Security Indicator Summary** section reports information on DNS traffic observed over the past 7 days on your network. The Security Indicator Summary presents a consolidated view of the most relevant threat signals and behavioral indicators detected during the reporting period. It aggregates key telemetry findings such as anomalous domain activity, known threat actor presence, and potential signs of data exfiltration or malware communication—into a concise reference point for security teams. 

This section is designed to quickly communicate where risks may be emerging across the DNS layer and helps identify early-stage threats or policy violations. By summarizing both quantitative data (e.g., DNS event volumes, flagged domains) and qualitative patterns (e.g., lookalike domains, domain generation algorithms), it supports rapid situational awareness. 

The goal of this section is to equip security analysts with a high-level threat snapshot, enabling efficient prioritization of investigations, policy tuning, and control adjustments.

| ### **Security Indicator Event Type** | ### **Description** |
| --- | --- |
| DNS Events | Total volume of individual requests/traffic analyzed. |
| Malicious Events | Number of malicious queries accessed. |
| High-Risk Events | Number of high-risk queries accessed. |
| Threat Actors | Known DNS threat actors detected with activity in your network. |
| Zero-Day DNS | Domains registered and launched within a small window. |
| DNS Tunneling | DNS tunneling can be indicative of data exfiltration or C2. |
| Lookalike from Custom watched Domains | Created to impersonate your brand for malicious purposes. |
| Domain Generation Algorithms | Indicative that malware exists and is looking to communicate "home." |
| Bandwidth Savings | Bandwidth saved from blocked traffic. |
| Unique Applications | The number of applications to verify against sanctioned list. |
| High-Risk Web Categories | illegal or policy-violating sites associated with potential data theft and other risks. |

## Threat Breakdown Summary and Key Findings

The goal of the **Threat Breakdown** section is to give users a clear, at-a-glance summary of the threat activity detected in their environment and how effectively Infoblox protected them during the reporting period. It highlights key protection metrics, such as **Protection Before Impact**, and compares them to global averages so users can quickly understand their security performance in context.

This section also breaks down the types and severity of threats observed—such as suspicious, malicious, lookalike domains, and other indicators—while summarizing the most important findings in a way that supports fast interpretation and decision-making. Overall, it helps users understand both the scale of threat activity and the value of the protection and detection capabilities working on their behalf.

| ### **Threat Breakdown Event Type** | ### **Description** |
| --- | --- |
| DNS Threat Actors | The number of DNS threat actor used to support malicious activities, distinct from the malware or individual campaigns, observed in the customer environment. |
| Zero-Day DNS Detections | The number of Zero Day DNS™ detections detected and blocked by Infoblox Threat Defense observed in the customer environment. |
| Protection Before Impact | The percentage of threats detected and blocked by Infoblox before they were first observed in the customer environment. |
| Threat Domains | The percentage of unique domains identified by Infoblox that were associated with threats and blocked in the customer environment. |
| Detected by Zero Day DNS | The percentage of Zero Day DNS threats detected and blocked by Infoblox. |
| Detected by Threat Insight | The percentage of threats detected and blocked by Infoblox. |
| Protected later | The percentage of threats detected and blocked by Infoblox protected after they were first detected. |
| **Notable Threat Domains** |
| Breakdown of threat domains (suspicious/malicious) | The total number of threat domains detected on the network determined to be **Suspicious** or **Malicious**. |
| Suspicious → Malicious | The number of suspicious domains determined to be malicious domains detected on the customer network during an evaluation period. |
| TDS | The number of TDS events of this type detected on the customer network. A Threat Domain Scope (TDS) is a way to define and manage groups of related threat domains for targeted protection. |
| Lookalike | The number of Lookalike events of this type detected on the customer network. Lookalikes  impersonate your brand for malicious purposes. |

| ### **Reported Event Type Reports** | ### **Description** |
| --- | --- |
| Threats Blocked | The distribution of threats observed and blocked categorized by threat class. |
| Threats Allowed | The distribution of threats observed but allowed per policy categorized by threat class. |
| First To Detect | Thiis shows Infoblox’s lead time in detecting threats by class, and related detections in your environment by Infoblox Threat intelligence (ITI). |
| Predictive Intelligence | This shows the distribution of suspicious domains that became malicious. |

## <span style="color: #000000">Downloading the Executive Summary Report</span>

<span style="color: #000000">To download the Executive Summary report, perform the following:</span>

1. <span style="color: #000000">From the Infoblox Portal, click </span>**Security** > **Reports** > **Summary Reports**<span style="color: #000000">.</span>
2. <span style="color: #000000">On the </span><span style="color: #000000">*Summary*</span><span style="color: #000000"> Reports page, complete the three-step process to export the </span><span style="color: #000000">*Executive Summary report.*</span>

<span style="color: #000000">**Step 1: Choose a report to generate:**</span><span style="color: #000000"> Select </span><span style="color: #000000">**Executive Summary Report**</span><span style="color: #000000"> from among the listed reports in the drop-down menu. </span>

<span style="color: #000000">**Step 2: Select a time period for the report you would like to download. You can select up to 30 days of data:**</span><span style="color: #000000"> Select the date range for the executive summary you want to download. Date ranges include the following:</span>

- <span style="color: #000000">1 hour</span>
- <span style="color: #000000">24 hours</span>
- <span style="color: #000000">48 hours</span>
- <span style="color: #000000">7 days</span>
- <span style="color: #000000">1 month</span>
- <span style="color: #000000">Custom. When a custom date range is selected, a date-time prompt will populate the page where you can select the date or dates you want to view. </span>You can choose up to 31 days of data, but only from the past 31 days<span style="color: #000000">.</span>

<span style="color: #000000">**Step 3: Choose page size**</span><span style="color: #000000">: You can choose from among three different page size options for your report. Choose your choice of report page size from among the options in the drop-down list. Report page size options include: </span>

- <span style="color: #000000">**Default**</span><span style="color: #000000"> (17.78 x 10 inches (452 x 254 mm))</span>
- <span style="color: #000000">**A4**</span><span style="color: #000000"> (11.69 x 8.27 inches (297 x 210 mm))</span>
- <span style="color: #000000">**US Letter**</span><span style="color: #000000"> (11 x 8.5 inches (279 x 216 mm))</span>

<span style="color: #000000">**Step 4: Export the Report: **</span><span style="color: #000000">Click the </span><span style="color: #000000">**Export**</span><span style="color: #000000"> button to download the </span><span style="color: #000000">*Executive Summary*</span><span style="color: #000000"> report in the selected page size as a PDF.</span>

<span style="color: #000000">The Executive Summary dashboard widgets can be viewed by adding them to the dashboard page.</span>

<span style="color: #000000">Sample Executive Summary Report (pdf)</span>