Suspicious communication over DNS

Copper Contributor

I have received a message mentioning Suspicious communication over DNS in my ATP. Why I am getting this error? While checking the activity different host name which does not belong to my organization is displayed. How to analyze this issue?

clipboard_image_2.png

1 Reply

@Reninraj , export the alert to excel, you will get more details about those source machines.

And see this guide for more details:

https://docs.microsoft.com/en-us/azure-advanced-threat-protection/atp-exfiltration-alerts#suspicious...