Skip to content

Secutec

You can integrate Secutec SecureDNS with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Secutec SecureDNS product overview

Secutec SecureDNS focuses on enhancing network security and integrity through the Domain Name System (DNS) security. Utilizing a cloud-based platform, Secutec SecureDNS offers centralized management of DNS traffic, scrutinizing and filtering requests to prevent access to malicious or unauthorized domains.

What we ingest

Sophos XDR collects Secutec SecureDNS data over HTTPS by polling the Secutec SecureDNS API, authenticating with an API token. The following data is collected:

  • DNS threat detections: SecureDNS Response Policy Zone (RPZ) alerts raised when a DNS query matches a threat policy list, such as malware and botnet domains, each carrying the matched threat list, the queried domain, the client, and threat category context.

Event and data types

We ingest the following event and data types from Secutec SecureDNS:

  • DNS threat detections: DNS lookups to malicious domains that SecureDNS blocked or redirected through its Response Policy Zones, such as malware and botnet domains, including the queried domain, matched threat list, client, and category. Normalized to third-party security alert telemetry.

Data provided by this integration

Data provided by Secutec SecureDNS gets normalized to the following schemas:

  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation