- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Content filtering weird issue
Hi folks,
We have content filtering set up on our MX, and it has suddenly started reporting that our Domain Controler is trying to reach pornographic sites at 3:33am most mornings. Our PDC is also our DNS server for the network.
We can't find any obvious cause for this. We aren't a 24 hour operation, so there is no one on the VPN or in the building at that time of the morning. The domain controller itself appears to be clean, and there's nothing in the DNS logs to suggest it's caching those nameservers for any reason.
Is it possible this is a false positive, or that it's coming from another machine on the network?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've scanned the server with Spybot S&D, and it has an EDR solution installed as well. Spybot found some tracking cookies and a registry entry that prevented the "Windows is checking for a solution" popups, which is slightly suspicious.
