---
title: "Comprehensive Security Report"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35406198/Comprehensive%20Security%20Report"
format: markdown
---
The *Comprehensive Security Summary Report* presents a high-level overview of DNS-based security events highlighting key threat indicators, behavioral trends, and intelligence-based detections across the network. It is intended to support proactive risk management, incident response, and continuous monitoring by summarizing threats, malicious domain activity, and system-level insights.

> ⚠️ **Note: **
> ⚠️ 
> ⚠️ All report data is obtained from your organization's security policy with the exception of lookalike data, which is obtained from your organization's lookalike configuration.

The Comprehensive Security Report is available to subscribers of Infoblox Threat Defense Business Cloud and Infoblox Threat Defense Advanced. The Comprehensive Security Report is not available for Infoblox Threat Defense Essentials or for Infoblox Threat Defense Business On-Premises subscribers.

The *Comprehensive Security Summary Report *includes the following content sections:

- Executive Summary
- Traffic Usage Analysis
- Key Insights
- Threat Actors
- Zero-Day DNS
- Industry Vertical Analysis
- Application Detection
- Web Content Discovery

| ## **Executive Summary**<br>Key Findings and Risks |
| --- |
| This section provides a high-level overview of the organization’s current DNS-based security posture. It summarizes major findings, including significant threat activity, key trends, and general observations from the reporting period. The executive summary is designed for stakeholders who need a quick, digestible snapshot of network risk.<br>For additional information, see *[Executive Summary Report](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35406182)*. |
| Critical Events | The number of malicious events observed |
| Critical Domains | The number of unique malicious domains (SLD) accessed. |
| Risky Domains | Detected domains that are likely to be used in a future malicious campaign. |
| Data Exfil / Tunneling | Detected activity associated with potential data compromise/loss. |
| Lookalike Domains | Created by threat actors to impersonate your brand for malicious purposes. |
| Zero Day DNS | Domains registered and launched within a small window. |
| Recommendations to Mitigate Risk | Infoblox recommendations to mitigate risk in your network.<br>Includes the following statistics:<br>- Avg Domain takedown within 24 hours
- Percentage alert reduction on EDR and NGFW
- The number of First to Detect domains
- The number of days avg Proactive protection |

| ## **Security Indicators Summary**<br>A summary of DNS traffic in your organization.** ** |
| --- |
| Malicious Events | The number of malicious queries accessed. |
| High-Risk Events | The number of high-risk queries accessed. |
| Key Insight | Actionable insights based on aggregated and correlated security event data. |
| Threat Actors | Known DNS threat actors detected with activity in your network. |
| Zero Day DNS | Domains registered and launched within a small window. |
| DNS Tunneling | DNS tunneling can be indicative of data exfiltration or C2. |
| Lookalike from Custom Watched Domains | Created to impersonate your brand for malicious purposes. |
| Domain Generation Algorithms | Indicate that malware exists and is looking to communicate "home." |
| Bandwidth Savings | Bandwidth saved from blocked traffic. |
| Unique Applications | Number of applications to verify against sanctioned list. |
| High-Risk Web Categories | Illegal or policy-violating sites associated with potential data theft and other risks. |
| The total number of events per day (on average) reported in your network. | The number of requests in total shows the importance of the DNS protocol for the IT infrastructure and the unique vantage point for visibility and security. |

| ## **Threat Breakdown** |
| --- |
| DNS Threat Actors |  |
| Zero-Day DNS Detections |  |
| Protection Before Impact | The percentage of threats detected and blocked by Infoblox before they were first observed in your environment. |
| Threat domains | The percentage of DNS queries to threat domains. |
| Detected by Zero-day DNS |  |
| Detected by Threat Insight |  |
| Protected Later |  |
| ### **Notable Threat Domains** |
| Threat Breakdown | The total number of threat domains detected on the network determined to be **Suspicious** or **Malicious**. |
| Suspicious → Malicious | The number of suspicious domains determined to be malicious domains detected on the customer network during an evaluation period. |
| TDS | The number of TDS events of this type detected on the customer network. A Threat Domain Scope (TDS) is a way to define and manage groups of related threat domains for targeted protection. |
| Lookalike | The number of Lookalike events of this type detected on the customer network. Lookalikes impersonate your brand for malicious purposes. |
| Threat Breakdown | Zero-Day DNS Detections |
| Notable Threat Domains |  |

| ## **Traffic Usage Analysis** |
| --- |
| The Traffic Usage Analysis section evaluates DNS traffic volume and categorizes it based on behavioral attributes. It provides visibility into how DNS is used across the network and helps determine whether any portion of the traffic may be tied to suspicious, malicious, or policy-violating behavior. | ## Traffic Usage Analysis Report<br>### Total DNS Activity<br>The **Total DNS Activity **section** **reports the total DNS requests during the assessment period. This represents the full DNS traffic volume reviewed for the period and provides the baseline for evaluating security activity, DNS Firewall events, and incident counts.<br>### DNS Firewall Activity<br>The **DNS Firewall Activity** section records the total number of DNS Firewall events. Firewall events are classified as High, Medium, or Low.<br>### Threat Activity<br>The Threat Activity section reports the number of unique threat indicators. This indicates that the assessment detected multiple distinct threat-related signals within the reviewed DNS activity.<br>### Data Exfiltration Incidents<br>The **Data Exfiltration Incidents** section reports the total number of **incidents** related to data exfiltration. These incidents represent detected activity associated with potential data movement, tunneling, or compromise indicators.<br>### Top Threat Feeds<br>The **Top Threat Feeds** chart shows the represented feed activity associated with Threat Insight - Data Exfiltration.<br>### Top Detected Properties<br>The **Top Detected Properties** chart also shows properties associated with Threat Insight - Data Exfiltration.<br>### Top Web Content by Type<br>The **Top Web Content by Type** section shows web content category data by type. |
| ### **Bandwidth Savings** |
| Bandwidth Savings measures savings from blocking bad domains. It provides the required protection and compliance while saving bandwidth and improving network performance. | ### Overall Bandwidth Savings<br>The report shows **the** total bandwidth savings. This indicates that blocked traffic prevented a significant amount of network usage during the assessment period. The information is presented in the form of a chart with a breakdown based on the events associated with the bandwidth saving. |

| ## **Key Insights** |
| --- |
| The Key Insights section include all security events are aggregated and correlated into actionable, prioritized insights. The Key insights section correlates and aggregates DNS telemetry and threat intelligence into prioritized, actionable security insights. It classifies insights by severity (e.g., critical, high, medium) and threat type to help security teams focus their investigations on the most relevant risks. | ### Insight Severity<br>- **Total Open Insights**
  - The number of **Total Open Insights **represents the total number of open insights residing on the network.
- **Critical Priority Insights**
  - This number of **Critical Priority Insights **represents the total number of critical priority insights residing on the network.
- **High Priority Insights**
  - This number of **High Priority Insights** represents the total number of high priority insights residing on the network.
- **Medium Priority Insights**
  - This number of **Medium Priority Insights** represents the total number of medium priority insights residing on the network.
- **Insight Distribution by Threat Type**
  - **Insight Distribution by Threat Type **represents how the open security insights are grouped by the type of threat that generated them (pie chart).
- **Event to Insight Aggregation**
  - **Event to Insight Aggregation** shows how individual security events are collected, analyzed, correlated, and reduced into a smaller number of actionable insights (infographic).
- **Malware Download Insight Details**
  - **Malware Download Insight Details** includes the following sections:
    - Active Period
    - What was observed in your environment?
    - Assets
    - Indicators/Events
    - Indicator report (a reports about a specific reported indicator)
- **Phishing Insight Details**
  - **Phishing Insight Details**  includes the following sections:
    - Active Period
    - What was observed in your environment?
    - Assets
    - Indicators/Events
    - Indicator report (specific report for the reported indicator) |
| ### DGA Insight Details |
| The report includes details of all Critical and High priority insights observed during the time period. This may or may not always include “DGA Insight Details.” | ### Active Period<br>The **Active Period** is the length of time the insight has remained active, measured from the Insight Creation Date to the Last Observed date.<br>### What was observed in your environment<br>The **What was observed in your environment **section identifies the threat activity detected in the environment, including the threat type, class, and associated malware or threat family.<br>### Assets<br>This **Assets **section shows the number of assets associated with the insight, including whether those assets are verified or unverified. It also indicates how many assets accessed unblocked indicators.<br>### Indicators / Events<br>The **Indicators / Events** section summarizes the indicators or events associated with the insight and shows whether they were blocked or not blocked. This section helps show the activity pattern over time and whether enforcement action occurred. |
| ### Zero-Day DNS Insight Details |
| The report includes details of all Critical and High priority insights observed during the time period. This may or may not always include “DGA Insight Details.” | ### Active Period<br>The **Active Period** section shows how long the Zero Day DNS insight has been active, including when the insight was created and when it was last observed.<br>### What was observed in your environment<br>The **What was observed in your environment** section identifies the detected activity type and classification.<br>### Assets<br>The **Assets** section shows the number of assets associated with the insight, including verified and unverified assets. It also shows how many assets accessed unblocked indicators.<br>### Indicators / Events<br>The **Indicators / Events** section shows the number of indicators associated with the insight and whether those indicators were blocked or not blocked. It also displays the indicator or event activity over the assessment timeline. |

|  |
| --- |
| ## **Threat Actors** |
| Reports specific threat actors discovered in the assessed environment. The section identifies DNS activity linked to known threat actors or attacker infrastructure and provides information about their tactics, techniques, and procedures (TTPs). This context supports threat attribution and response planning. | **Threat Actor Assessment**<br>- Activity timeline
- Correlated indicators
- Synopsis of targets<br>**Summary**<br>- Threat Actor Count for the selected period
- Average Time Advantage across all threat actors, reported as Average Time Advantage Ahead of Industry
- Total Attempts |
| **Threat Highlights** |
| Displays dynamic information cards for the three threat actors with the most attempts in the customer environment. | The secondary area of each card includes the following information.<br>- Threat Actor Count for the selected period
- Average Time Advantage across all associated indicators, reported as Average Time Advantage Ahead of Industry
- Total Attempts |
| **Top 10 Threat Actors** |
| Lists the ten threat actors with the most attempts. | The table includes the following columns.<br>- Threat Actor Name
- Threat Property
- Attempts
- Average Time Advantage
- Domains, shown as Seen in Network/Total Domains |

| ## **Zero Day DNS** |
| --- |
| The Zero Day DNS section highlights newly registered domains that have been detected in the environment before being widely recognized by threat intelligence feeds. These “zero-day” domains are often used in early-stage attack infrastructure and may be indicators of emerging threats. | ### Summary<br>- Total Unique ZDD Domains: The total number of unique Zero Day DNS domains.
- Suspicious Domains (of those unique ZDD (Zero-Day DNS domains) detected): The percentage of suspicious domains.
- Malicious Domains (of those unique ZDD domains): The percentage of unique, malicious Zero-Day DNS domains.<br>### Suspicious and malicious Zero-Day DNS Domains<br>- The top five suspicious and malicious domains in your network.
  - SITE
  - DETECTION TYPE
  - HIT |

| ## **Industry Vertical Analysis** |
| --- |
| The Industry Vertical Analysis section benchmarks the organization’s DNS activity and threat indicators against others in the same industry. It provides comparative metrics to help assess whether the organization is experiencing higher, lower, or typical levels of risk relative to industry peers. | **Malicious Indicators Seen** (including *Your average* and the *Average across customers within your industry*.<br>- Example response: In the last 7 days, lnfoblox has observed 2 indicators that are malicious - 100% of those malicious domains and 0% are malicious IPs.<br>**Risky Indicators Seen** (including *Your average* and the *Average across customers within your industry*.<br>- Sample response: In the last 7 days, lnfoblox has observed 7 risky indicators in your environment - of which 30% is high risk, 50% is medium risk and 20% is low risk.<br>**Threat Actor Associated Traffic Seen** (including *Your average* and the *Average across customers within your industry*.<br>- Sample response: In the last 7 days, lnfoblox has observed 14 Threat Actors in your environment. 21% of your traffic is associated to those Threat Actors.<br>**Zero-Day DNS Traffic Seen** (including *Your average* and the *Average across customers within your industry*.<br>- Sample response: In the last 7 days, lnfoblox has observed 4 Zero Day DNS domains in your environment.<br>**Threat Insight Detection** (including *Your average* and the *Average across customers within your industry*.<br>- Sample response: In the last 7 days, lnfoblox has observed 32 indicators that are threat insight detection - 67% of those DNST domains and 34% are DGA. |

| ## **Security Activities** |
| --- |
| The Security Activities section surfaces DNS queries that may indicate security-relevant events. It classifies traffic into severity levels and includes insights from DNS Firewall detections and other security policies applied to DNS-layer traffic. This section includes the following: | ### **Security Activities Summary**<br>- **Security Events**: The number of security events.
- **DNS Firewall**: The number of DNS Firewall events.
- **Web Content**: The number of web content events.
- **Devices**: The number of devices on the network.
- **Users**: The number of users on the network.
- **Threat Insight**: The number of reported threat insight events.
- **Threat View**: The number of reported threat view events:
- **Source**: The number of reported sources.<br>### **Security Activities Analysis**<br>Devices having a high threat level<br>This section includes possessing a high threat level.<br>**Summary**:<br>- **Device Name**: The name of devices on the network.
- **Requests**: The number of requests associated with the incident.
- **User**: The number of users on the network.
- **Source**: The number of reported sources.
- **OS/Version**: The OS and version associated with the incident.
- **DHCP Fingerprint**: The  DHCP fingerprint associated with the incident.
- **MAC Address**: The MAC address associated with the incident.<br>### **Security Insights**<br>The most active threat type seen in current traffic associated with the endpoint count attempting those connections.<br>- Includes the following reports:
  - **Top indicators based on Threat Feed**: Most active indicators seen in current traffic
  - **Top Threat Types**: The most active threat indicators found in current traffic, correlated by threat type.<br>**Summary **(applies to both the above reports):<br>- Top indicators based on Threat Feed
  - **Threat indicator**: The threat indicator observed on your network.
  - **Feed name**: the name of the feed where the indicator was first detected.
  - **Events**: The number of events associated with the indicator.
- Top Threat Types
  - **Threat indicator**: The threat indicator observed on your network.
  - **Feed name**: the name of the feed where the indicator was first detected.
  - **Events**: The number of events associated with the indicator.<br>### **Threats Blocked**<br>The distribution of threats observed and blocked. Categorized by threat class.<br>**Summary**:<br>- Top Threats Blocked
  - **Threat Class**: The blocked threat’s threat class.
  - **Occurrences**: The number of occurrences of the blocked threat observed on your network.
  - **Detections**: The number of detections of the blocked threat observed on your network.<br>### **Threats Allowed**<br>The distribution of threats observed but allowed per policy. Categorized by threat class.<br>**Summary**:<br>- Top Threats Allowed
  - **Threat Class**: The allowed threat’s threat class.
  - **Occurrences**: The number of occurrences of the allowed threat observed on your network.
  - **Detections**: The number of detections of the allowed threat observed on your network.<br>### **First to Detect**<br>Infoblox’s lead time in detecting threats by class, and related detections in your environment by Infoblox Threat intelligence (ITI).<br>**Summary**:<br>- Top First to Detect
  - **Threat Class**: The first to detect threat class.
  - **Occurrences**: The number of occurrences of the first to detect threat class observed on your network.
  - **Avg. Infoblox Time**: The average time Infoblox detected the threat class before competitors did.
  - **Avg. Protection Time**: The average amount of protection time Infoblox afforded Infoblox customers before competitors did.<br>### **Predictive Intelligence**<br>The Predictive Intelligence section shows the distribution of suspicious domains that became malicious.<br>**Summary**:<br>- Top Predictive Intelligence
  - **Threat Property**: The threat property for the suspicious domain identified using predictive intelligence.
  - **Occurrences**: The number of occurrences of the suspicious domain observed on your network identified by predictive intelligence
  - **Attempts**: The number of attempts of the suspicious domain observed on your network identified by predictive intelligence.
  - **Time Advantage**: The amount of time saved using predictive intelligence in identify the suspicious domain. |

| ## **Application Detection** |
| --- |
| The Application Detection section monitors and categorizes DNS activity generated by applications on the network. It helps organizations identify both approved and unauthorized application usage, supporting visibility into potential shadow IT or policy violations. | ###  Categorized Application Traffic Detection<br>- Name
- Category
- Requests
- Status
- Devices
- Manufacturer |

| ## **Web Content Discovery** |
| --- |
| The Web Content Discovery section analyzes resolved web destinations based on DNS traffic, categorizing them into content types such as acceptable use, high-risk, or policy-violating. It aids in enforcing acceptable browsing policies and detecting risky behavior tied to credential or data exposure. | ### Categorized Web Traffic Detection<br>- Sub-Category
- Category
- Requests
- Devices |

| ## **DNS Tunneling Insight ** |
| --- |
| The DNS Tunneling Insight section displays DNS tunneling insights as a dashboard-like infographic. | ### DNS Tunneling Insight Details:<br>- Active Period: The active period measured in days.
- What was observed on your network.
- Assets: The total number of assets.
- Indicators/Events: The number of  threat indicators, both blocked and not blocked.
- indicator panel: This displays detailed information on reported threat indicators:
  - Indicator name
  - Number of assets associated with the indicator
  - 
  - Indicator threat level (High, Medium, Low)
  - Last and first dates and times of observation. |

| ## **Lookalike Domains** |
| --- |
| The Lookalike Domains section provides active monitoring for lookalike domains of major brands, including common typosquats. It includes custom monitoring for lookalikes impersonating your brand for malicious purposes. | ### Categorized Lookalike Domains<br>**Summary**<br>- Total Lookalikes
- Total Lookalikes from Custom Watched Domains
- Total Threats from Watched Domains<br>**Lookalikes By Threat Types**<br>- Suspicious
- Phishing
- Malware C2
- Others |