Forum Discussion
DNS reconnnaissance tests cannot be seen during the 8-day Learning Period
Hi Chuck99 ,
The DNS activities supposed to be displayed in the computer timeline, not in the general alert timeline. Are you looking at the source computer profile you originated the DNS activities from. and there are no such activities? You can use the filter to look only at DNS queries. If this is the case please contact me privately with your tenant details so we can look at it.
The learning period are not configurable.
Thanks,
Tali
- Chuck99Sep 12, 2019Brass Contributor
Hi Tali Ash
That's exactly right. I don't see the DNS activity in the source computer timeline. When I search for the source computer from where I did the DNS reconnaissance tests (pointing nslookup to the DC on which the ATP sensor is installed), I see other activities like logins or even SMB activities but not the DNS activities. Same thing if I run other reconnaissance commands like "net user /domain" or "net group "domain admins" /domain".
I'll send you a private message with our tenant info. Thank you very much for your help with this.