Malwarebytes DNS server false positive?


hello, i'm hoping here can me this. i'm rookie @ stuff, company best can. have malwarebytes business installed on every computer in our company including our server called wcncserver. server our dns , dhcp server. think when tries access bad site notified wcncserver had website blocked. assume because of traffic going through server.

how can identify rogue user or computer? assume if company computer malwarebytes have identified site on company computer , notified me before ever made wcncserver. not have wifi it's not mobile device.

have tried wireshark, shows wcncserver 1 trying access malicious website.

i've contacted malwarebytes , they've told me malwarebytes blocking threat, not identifying culprit. thing i'm interested in finding rouge computer.

 any ideas?

thank you.

hi; need kind of proxy server or firewall determine host endpoint accessing malicious web site if malwarebytes can't this.  there many choices available out on market.


best regards, todd heron | active directory consultant



Windows Server  >  IPAM, DHCP, DNS



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group