← Blog

Securd Greywall: advanced DNS filtering and threat hunting

How Securd's Greywall revolutionizes DNS filtering and threat hunting by holding first-seen domains for review.

DNS filtering has operated on the same principle for two decades: maintain a list of known-bad domains, block them, allow everything else. This blocklist model worked when the internet had millions of domains. It breaks when 300,000 new domains are registered every single day and threat actors use disposable infrastructure that exists for hours before burning.

Securd's Greywall represents a fundamental shift in DNS security philosophy. Instead of asking 'is this domain known to be bad?' it asks a different question: 'has this organization ever seen this domain before?' If the answer is no, the domain is held for review. Not blocked outright — held. This distinction matters because it creates a third state between allow and block that traditional DNS security doesn't offer.

The Greywall operates per-tenant with complete isolation. When Tenant A's endpoints query a domain for the first time, only Tenant A's Greywall is triggered. Tenant B may have seen that domain thousands of times. This per-tenant model ensures that each organization's Greywall reflects only their own DNS behavior — not a global average that dilutes security for everyone.

Learning mode is the entry point. When you first deploy Securd and enable Greywall, it runs in learning mode for 7-14 days. During this period, it observes every DNS query from your network, building a comprehensive baseline of domains your organization normally resolves. Microsoft 365 domains. Google Workspace. Your SaaS stack. Your cloud providers. All of these become known-trusted during learning.

When you switch to enforce mode, the Greywall becomes active. Any domain outside your learned baseline is held. The first few days generate a review queue as edge cases appear — a new vendor's domain, a legitimate service that happens to use a CDN domain your organization hadn't queried during learning. Approve these, and they're permanently trusted. The queue shrinks rapidly.

For threat hunting, the Greywall is transformative. Traditional DNS threat hunting asks analysts to search through millions of allow events looking for anomalies. The Greywall does this automatically — every anomaly (first-seen domain) is surfaced to the review queue. Analysts spend their time evaluating pre-filtered suspicious domains rather than searching through haystacks.

The Greywall excels against specific threat types. Phishing domains: 84% are less than 24 hours old, making them first-seen by definition. DGA domains: malware-generated domains that are random strings — always first-seen. Newly registered C2 infrastructure: threat actors register fresh domains for each campaign — always first-seen. Typosquats: newly registered lookalike domains targeting your employees — always first-seen.

Organizations running Securd's Greywall in enforce mode typically see a 95% reduction in effective domain exposure. Out of the millions of domains on the internet, your organization resolves only a fraction. The Greywall ensures your endpoints can only reach those trusted domains — plus anything you explicitly approve. This is zero-trust applied to DNS resolution, and it's a capability that no other DNS security vendor offers.

Evaluate Agent DNS with your own agent traffic

Deploy on a single policy in learning mode and review the results with your security team.