NetFlow / IPFIX
Use detailed flow relationships for capacity, application and source-destination analysis.
Detect open-resolver exposure and monitor address reputation across selected DNS blocklists.
Run scheduled subnet scans, record list-specific results and follow remediation using status, error and last-check information.
Begin with the global condition, narrow the scope by direction and subnet, identify the responsible source and destination relationship, and compare the result with historical behavior before taking action.
This module uses the same inventory and telemetry model as realtime analytics, security controls, historical reporting and BGP operations.
Use detailed flow relationships for capacity, application and source-destination analysis.
Maintain scalable traffic and PPS visibility across high-speed, high-port-count environments.
Add focused packet-copy visibility for critical services, VLANs and investigation points.
IP addresses and flow counters become easier to interpret when they are connected to DNS behavior and reputation evidence. Flowtrion brings these signals into a single investigation path for NOC and SOC teams.
The module uses IP and domain indicators derived from traffic investigations, together with configured DNS and DNSBL lookups. Query results should be treated as contextual evidence because reputation lists have different coverage and update policies.
Teams can review resolution status, reverse-DNS context and list matches while investigating scanners, suspicious SMTP senders, command-and-control candidates or unusual external destinations.
Use reliable resolvers, define timeouts and cache policies, and monitor lookup failures. A DNSBL match should be validated with traffic behavior and other evidence before enforcement.
DNS and DNSBL results complement SMTP, anomaly, top-talker and spoofing investigations and can be included in incident or escalation records.