A Live Demo of Infoblox Threat Defense
This hands-on session follows the earlier briefings and goes straight into the Infoblox Security Portal. We’ll trace malicious activity from first DNS lookup to automated enforcement, show how verdicts are backed by Infoblox Threat Intelligence, and walk through incident triage and policy tuning. Expect practical coverage of policy creation, exception handling, and integrations that extend protection across endpoint, network, and cloud. You’ll leave with a clear view of day-to-day operations and the metrics that matter. Speaker Kevin Zettel began the demonstration by outlining the five flexible deployment options for Infoblox’s threat defense solution. These include a lightweight endpoint agent for rich user attribution, physical or virtual NIOS appliances, NIOS as a service with IPsec tunnels for cloud and SASE environments, and a simple external resolver configuration. Zettel emphasized that these methods can be mixed and matched, and even without an endpoint agent, the system uses Universal Asset Insights to enrich data, providing crucial context like the specific device, user, and MAC address for every DNS query. He also confirmed that Infoblox provides comprehensive threat feeds for IPs, URLs, and hashes that can be exported to firewalls to counter adversaries who might pivot away from DNS.
Transitioning to the live portal, Zettel showcased the main dashboard, which provides immediate KPIs on the security of the DNS infrastructure. He highlighted the value of “predictive intelligence” and a key metric called “first to detect,” which demonstrates to customers that Infoblox knew about malicious domains on average several weeks before an employee ever clicked on them. The portal offers a detailed, asset-centric view, allowing security teams to identify at-risk devices, trace their entire IP address history across the network, and review all associated security and policy violations. This capability is critical for incident triage, enabling an analyst to quickly understand the scope of an infection and identify other potentially compromised systems by seeing everywhere a device has been.
To demonstrate how security verdicts are backed by intelligence, Zettel navigated to the threat intelligence section, which shows customers which specific threat actor “cartels” are active in their environment and the exact malicious domains their users have accessed. To make the massive volume of DNS data actionable for security operations (SOC) teams, he introduced an AI-powered feature called “Insights,” which automatically correlates millions of individual events into a handful of manageable incidents. For deeper investigation and policy tuning, the integrated “Dossier” research tool allows an analyst to click any indicator (domain, IP, etc.) and receive a consolidated report from over twenty different tools, providing the full context needed to validate a threat and make informed policy decisions.
Presented by Kevin Zettel, Associate Manager, Technical Marketing. Recorded live at Security Field Day 14 in Silicon Valley on September 24, 2025. Watch the entire presentation at https://techfieldday.com/appearance/infoblox-presents-at-security-field-day-14/ or visit https://techfieldday.com/event/xfd14/ or https://Infoblox.com for more information.
Transcript
I'm gonna throw my best to follow up with everything you just talked about quite a bit. Um, we're just going to get a little glimpse of everything and there's a lot, right? And it's all around DNS.
But before that I do want to explain kind of the deployment options. There's about five different options we have. Each one is unique to every single customer and it doesn't matter how you wanna do it, but we could do any one of the five options.
And the first one is always an endpoint. Endpoint. We like a lot because we get all the user attribution data really easily with an endpoint.
And customers like it too. 'cause they have UDM devices to deploy it across really quickly. Put on a Mac, windows, iPhones, Androids, you name it, right?
Makes it really easy for them. However, not every customer likes endpoints 'cause they always say, Hey, I don't want another endpoint on my devices. So we have four other options for those kind of customers.
And the first one's gonna be, uh, nios X server physical or virtual that we can play as an edge device anywhere in their network. So that could be an A-W-S-G-C-P Azure, it could be hardware, right? You can deploy it on-prem as A-K-V-M-O-V-A file onto a VMware.
Doesn't matter. And, and they're lightweight edge devices that you can deploy hundreds of them. And we have config profiles you can assign to multiple of them.
And then we also have nios, which is our pride in tested and true product that's been around for a very long time. And we can deploy DPS on that as well to send it directly to our cloud. Or for some of our customers, they can't use our SAS product.
You can actually download these feeds and run a lot of this stuff OnPrem itself. So rather than having us manage everything, you can actually manage yourself OnPrem. And then the fourth option, which is newer ish, it's been around for quite some time at this point, it's now X as a service.
So if you're using things like an SD WAN vendor or SASS e products and you want to connect directly in, you can actually create IPSec tunnels directly to us. We can run s the DHP and DNS service directly to those, uh, sd-wan, SAS E products. Or if you're using a cloud vendor, we can connect directly to the cloud service.
So it would be cloud to cloud. We actually host these on our side and you just create the IPSec tunnel to us. And then the last option is an external resolver, which is unique to threat defense.
It's like an open resolver except for you have to tell us what your public IP addresses are. And then we start ingesting any traffic coming from those public IP addresses. Really easy to deploy.
Only downside is we don't get all the user attribution data directly from those queries. However, we have things around the universal asset insights. And so as we ingest a lot of this information from our nios, from UDDI, from other third party vendors as well, Google Cloud, Azure, AWS, we actually take that information and we'll see it in the demo.
We take that information and in each packet we tell you what device made that query, give you the MAC address and everything else around it give you the context around everything that you're seeing. We'll see that. I just wanna make sure that we have the understanding of the five different deployment options.
Everything's mix and match. You can use multiple deployment options. You can deploy stuff on-prem in the cloud at the same time.
You can have endpoints, people leaving the network coming back on. It's all up to the customer use case. We have everything.
We got a question for you. Yeah. So if a adversary gets in, it's automated malware, they do a DNS lookup, you guys are cutting 'em off of the knees, right?
If an adversary gets in and it is a person and they do a DNS lookup, you guys are cutting off of the knees. If an adversary gets in and it does a DNS lookup and it's a person and it's cut off in the knees, I'm seeing my adversaries very quickly change to IP addresses. So do you have any sort of lead or feed from your threat intelligence that could consume either at my XDR or at my firewall or somewhere else?
You actually do. And so I'll show that as well. Unique to info boxes, we share all of our feeds.
We don't just share the DNS, we share our ip uh, URLs, um, hashes, everything we have, we share with you. So we don't hide it. There's nothing behind the scene.
You wanna say something else? Yeah, I just wanted to say we do have, you know, IP thread feeds. Yep.
First of all, we don't see a lot of attacks using ips. The reason is just like, um, you know, all the good companies are trying to use domains to scale things. Um, IPS will be very hard.
Attackers are the same way, right? So we don't see a lot of attackers using ips. We see them using BNS, But we've had a number of events over the past 18 months, okay.
Where, because we're starting to harden our DNS Oh, okay. The, the adversary starts at DNS sees DNS isn't working, switches it up. I see.
Okay. So completely agree with you. The starting point is always DNSI see.
Um, but if it's a human there and they know, ah, these guys seem to have it, you know, some security, all right. So I'm glad to know you have the export too, that Possible. Yeah.
So we, we have the feeds, um, but because that connection will not come to the DNS server, we can't block it. So what customers do is put those feeds on the firewall. Yeah.
Yeah. Because we are just not in the path of traffic at that point. If they switch to IP And then if they're off network, I've got other problems.
Yeah. Correct. Yeah, correct.
Love that though. Cool. Thank you.
I'm gonna walk you guys actually through the light demo now. So I'm gonna sit down and, uh, go through this. It is live, but anything that can go wrong will go wrong.
We do believe, forgive me, um, we're gonna go through as much as is we can again, uh, SSH talked about a lot of things and we're gonna get through as much as possible. I'm gonna hide this guy as well. So it's off my screen.
Cool. All right. So this is, uh, the portal that you see when you first log in to Threat Defense.
Uh, we have the KPIs for the entire DNS infrastructure on the security side right away. Uh, and we can see right away some pretty obvious things we think of when DNS protection. We have different types of categories, malware, DGA, malicious, notional data exfiltration stuff that we just block right away for you guys.
Um, we don't have anything that's allowed to right now in this demo environment, but if you did see things going through, we would alert you right away for it. And it's important for your team to know, hey, what's going through. But what's also cool about this is one of our key competitors is a good enough solution.
And what we want to provide to you right away is what we call predictive intelligence. And what's cool about this is eSSH talked about the suspicious feeds we have. I'll show you the feed.
There's like 17, 18 million records in there. Those eventually get turned into categories that we've watched, right? So right away we know it's malicious because they're your cartels putting out all these feeds.
We know they're malicious, we just don't know which category fits in yet. And over time we'll adjust to it and say, Hey, this was within a DGA or an emerging domain or a, a simple, a generic, right? But this is to this specific customer account.
Those, those suspicious domains eventually do get clicked on. What eventually do they turn into, right? And of course we have the threats by the level.
Uh, this is typically what you think of when you're thinking about DNS, but, uh, the different types, suspicious, malicious, phishing, the different categories, high and low. Your team knows right away what's going on in your network. But also the first to detect, uh, again, a good enough solution is, is people are just putting feeds out there.
But we're saying, Hey, when you clicked on it, how much earlier did Infoblox know about it before you clicked on it? And we're showing our customers right away in this case, in this demo environment, seven weeks before they clicked on that domain, on average or suspicious type of events, we knew about it and we protected you on average. And that could be up or down depending on the customer account.
Um, and you know, other ones like malware. So three weeks, uh, malicious, it's five weeks. And then we have bandwidth savings.
Another thing that you don't think about with DNS is as we stop these domains, a packet for DNS is really lightweight. That HTPS request, the video, the download, all that stuff adds up bandwidth in your traffic. And if we can save that on your firewalls and your routers, that's another money savings for your, your security team and your networking team.
Cool. That's, that's the threat side of it. And I, I didn't actually get into anything specific for the assets.
So we're gonna jump right over to the assets. And what's cool is with the Universal Asset Insights and this ingestion from nios, from UDDI, the DHP logs, we're actually able to see all the users and where they're going. So not only do we know the DNS packet, we know who exactly made that query.
We'll jump into some of these. In this case, we have, uh, at risk assets, assets are, we're making these large amount of requests that are malicious and normal infrastructure. You have thousands of devices and these are live assets.
These aren't assets that are on the shelf somewhere. These RPIs who are connecting to your network. In this case, we know this guy has two IP addresses.
'cause we discover it. We have two Mac addresses with this device. We know the operating system, the serial number behind it, the management addresses that he is been on.
And what's cool is we can also see all the security and policy violations he's made throughout his lifecycle. If we were to look at any one of these, uh, in this case, it's just suspicious. But we can see the first and last attempt when this has occurred.
In this case, there's two attempts. So we know one happened on 9 22 at six 18 and the same one happened. So they probably double clicked on this one.
And then let's say we know that, hey, this was the what infected this guy. Like we went back, we researched it, we know who to knock on their door, we found him. We say, Hey, where else has this guy been since that date?
We have the whole history of every single IP address where he's been in your network. So you can check every single one of those networks now and see where, what other devices that might have hopped onto. Right?
Maybe you downloaded something, it got out in through your network 'cause now it's in your network. Which networks do you need to go look into? We have all that context, right with, right with the DNS going back to the monitors tab, more step, go do the assets.
Uh, we also have assets by location. So if you have East Coast, west Coast, um, offices, some in Europe, you'll be see which ones are causing the most instance. Uh, something that's really valuable.
You know, countries in that are at war right now, Ukraine or Russia, if you have offices near that location, maybe they're getting hit more. That'd be something good to know about at risk by threat level. Again, things you think about, but you can again click into any one of these and it'll give you all the context but also all the assets associated with it.
You can deep dive into every single one. The Mac addresses, the ips, the management, any kind of security violations and policy violations. So if you have custom lists that you created, you can check which ones they're violating, including category filters.
So you can say, Hey, I wanna know who's going to social media sites or, uh, looking up stuff at work or you name it. Or for schools, right? Kids are going to sites they're not supposed to.
You need to report on that. That's a requirement, right? You can start checking out what devices within your school are going where, including the user information.
'cause we do collect the host name, right? This would be for my laptop. We have client oh two here.
It's a demo, but it was my laptop. It would say K zl. And it would actually tell me, Hey, K zl is going to these sites at this time.
It actually knows who I am. So can I enrich that data? You mentioned classrooms, right?
So could I, if I had a CSV or whatnot of these hosts belong to these schools, or if I'm on government, I'm like, all right, I got 14 agencies I'm gonna report out by agency. Can I enrich this data and do that type of reporting? Absolutely.
Yeah. Yeah. And, and there's a lot of ways to do that and yeah.
Yes. Okay. Thank you.
Cool. Great question. Um, that's it on the monitoring.
Uh, I think, lemme go back to assets. Make sure I didn't skip over anything I wanted to touch on. Um, yes, I think we're good here.
I wanna jump in 'cause SSH kind of talked about these cartels. Um, I wanna jump into those guys. Kind of the secret sauce.
Dave Mitchell will be talking a little bit more the secret sauce, but I do wanna show it in the portal here. We actually, again, a lot of this stuff is we're competing against good enough solutions and we need to show you guys within the portal itself what's going on within your network. If we jump right into the threat intel in our reporting, every customer will actually have the cartels that are in their network that they're clicking to and getting to right in here.
6. This is a demo lab. It's to that specific account, right?
So every customers will be up or lower on average to 60 days to get that point. But these are their cartels. So you can see vi uh, vi Viper with 25,000 records.
And what's cool is Infoblox tells you, Hey, which of those 25,000 records that we know about did your account click on? In this case we have 273 records for this demo account. And that could be useful if they're targeting your, your company and your organization.
Now you know exactly which records your company and your employees are clicking on. Customers in your network are clicking on. And it also tells you how far ahead of everyone within Avir virus total, by the way, is this conglomerate of a bunch of fees.
You can go out and purchase all of those, but we're showing you, hey, how much further ahead of all these guys are we, we look at this 1 59 days ahead, eight days ahead. And even if, by the way, I have found it once where Virus Toll did beat us, right? And we still show that.
We'll tell you if they beat us, how very rarely does it happen? That's why I'm pretty confident clicking through here. But we show you, you know, and we can see the average up here, right?
6 days where all these within this demo environment, And it also looks pretty cool 'cause you can also leverage it as almost like a, uh, like with all this data that's being ingested, you can use it to take it back to the higher ups and like, hey, maybe we focus on security hardening in these particular areas if we're clicking on these links and securing those a little more too. So that looks pretty interesting. Yep.
Yep. Uh, and there are reports for that, by the way. We have reports.
Yeah. Like you can generate those reports and provide 'em. And if you're, you're briefing something like this to clients that are less technical, knowing your enemy makes things a lot more realistic to someone who maybe doesn't understand the tech, but they're gonna know, oh, well I can see they put a name and a face on it.
Absolutely. Yeah. Put a name and a face to the cartel itself who is attacking you.
And, and some of these guys do have faces behind them. If you talk to Dave Mitchell after this, he can, uh, give you some very interesting stories. So there are people behind this that make a lot of money.
Uh, it's interesting. And of course, let's say, Hey, we are attacked. We want to know about more about this threat actor.
We give you publications about exactly what they're doing, how they're handling it, our threat intel team create these reports. Some of these are like hundreds of pages long. You get really good detail.
Send that off to your ciso, whoever else needs to learn. Your SOC team can now start learning what they're doing in your infrastructure. Cool.
So we talked about it. We kind of saw the threat actors, like 25,000 records, 30,000 records. There's a lot for each one of these cartels.
Um, what I want to jump to is actually our Tide itself. And I mentioned it briefly, in fact, it was asked, you know, do we have ip uh, lists of, of the bad domains? And we do, we have all that stuff and we share it.
We share all out. It's not hidden. But once you have threat defense, you can actually download all these fees, use 'em in your firewalls, use 'em where else you want.
What I want to show right away is, is we have millions of records in here. I'm gonna jump right into suspicious and you can see I like to use this page 'cause it shows us the exact number really quick. These update all the time, right?
We refresh these, these aren't just stale records. We're always looking at them. There's a whole process behind it, but we can get into more detail.
But you can see 17 million records just in our suspicious list. If you try to pull that down, put it into your firewall, you know, those guys at Penn are gonna be really happy. You're gonna be paying a lot of money, right?
Anywhere else people want you. Yeah. They want you to put these that we were, they would be pennies compared to what you'd be paying for on Infobox, right?
So you don't want to just download everything, put it somewhere random. It's gonna cost a lot. It's gonna be, make me really happy as a sales guys if you are gonna all those feeds into my firewall, I'll tell you that.
But that's the idea. We have these feeds. We open it up, put 'em wherever you want.
You know, we're, we're not shy about it. We don't hide it. Uh, I don't know why we share it so openly, but we do.
And it's, it's, it's good, good for our customers. Uh, and then the last second thing after that is I wanna show, you know, kind of what your SOC team is gonna be looking at and the reports itself. So we actually go back to our reporting and our security.
Uh, we actually store and, and this is a huge thing for SOC teams, is there's millions of DNS requests. We store all that on our side. You don't actually have to store that inside your sim that can increase the price.
But we store all that information for you, give you all the context for each and every single query, the device name, the ip, everything about these guys. Then your So team says, Hey, I have 30 million or 20 million DNS events. How am I supposed to correlate that?
No team is going to be able to handle that. So Info Walks has developed something called insights. And this is where our AI LLM machine learning comes into place.
And we take all of your events specific to your customer account. We call 'em insights. And we say, Hey, these grouping of DNS events from these devices are all related.
And that could be because they're all querying about the same time. It could be because they're all query the same grouping of domains. They're all coming from the same threat actor.
A lot of different use cases, the size of your company determines whether or not an insight tips trigger. This is a demo lab will have less events. A larger customer with millions of records will, it would take a little bit more to trigger an insight.
'cause it's just so much data going through here. We have five total assets. So it tells us right now with these, I don't know, 50, 50 plus total indicators, these events, they're all related somehow, right?
This is that AI in the back end and we're saying, Hey, and you can jump into it. Look at every single one of these assets exactly who they're the Mac addresses, again, just what we were showing earlier. And then also get each and every single one of these indicators, whether or not you're blocking it, not blocking it, where it's in your policies, which locations.
And something we get a lot too is, hey, sure, Infoblox says it's malicious. How do I know for a fact? Like I wanna, I wanna research this.
I wanna make sure before I, you know, enable it maybe, right? Because sometimes these come back and not block. I wanna make sure this is malicious and we have things baked in that you saw it a few times.
We had this little symbol. It's our research with Dossier. We have inside the tool baked in everywhere at any time.
You can click on any of these indicators and it will show you right away, Hey, this is why it's malicious, this is why we say it. The whole history behind it with like 20 plus different tools all into one. And you can go in and deep dive into the specific events.
I clicked one on random by the way. Right? But we can see the events behind it even gives you a little bit of information about exactly what's going on with this domain.
When we detected it all the, uh, PD NS information history, the who is data related domain. So if there's a threat actor and there's related domains to the incident or to the domain itself, we'll pop that off including related ips. So if you, you see the same related IPS together, that will pop up in here And I would imagine rhetorical, but in addition to being able to provide all the info, it has a quarantine feature.
So you could just kind of hold it up there and just stop it before doing the research and then you'll know, okay, this is safe. Or maybe kind of where to where to move it next. Uh, quarantine meaning Like, like, so if, you know, if you note a file or if you notice a data source and you're like, okay, what's the active threat level on this?
Like, you can kind of pretty much just stop it and Yes. Yeah. Yeah.
So we, we have our own custom. So this is, yeah, the question is, hey, a certain level we can block based off a certain level, right? Absolutely.
Yeah. Okay. Some even then sometimes it's not trusted, but we do have that tool baked in.
Go check it out, confirm it for yourself. What's So There's a baked in sandbox, huh? Is it like a baked in sandbox?
It's, it's a tool of tools. So it's combining all these other DNS tools into one single tool. You can just research it right inside our portal.
It's like a Multipurpose. Yeah. When You say 25 tools in one, What do you mean by that?
So for example, for example, the Hoorah, who is data? The who is records information? Uh, the Mitre attack surface is that there is one.
My history isn't showing up for me unfortunately. I don't know why. Uh, but I would actually be able to show you a, a really cool, uh, domain with it and it'll give you some more details.
Uh, we have a timeline behind it. These are all other tools that we're pulling from, including our own threat intel team. You know, just stuff that Dave Mitchell's gonna talk about.
They use these tools as well. They're custom built. You go and research and figure out, hey, are these domains malicious.