Why DNS Security and Threat Detection Need to Work Together

By Erik Linask

Security teams are accustomed to playing defense against long odds, but the pace of today’s threat activity is making that job harder.  According to DNSFilter’s 2026 Annual Security Report, an average user may now encounter 66 malicious domains a day, compared with 29 in the previous report — an increase that reflects both heavier internet usage and a continuing rise in malicious traffic.

Speed is part of the problem.  More than 65% of the unique threat domains DNSFilter observed were newly created, often used briefly and discarded before conventional reputation systems or static blocklists could catch up.  Upcoming research from Blumira also points to attacks increasingly crossing multiple systems and stages of the MITRE ATT&CK framework, making it harder to treat a malicious domain, endpoint alert, or identity event as an isolated incident.

Prevention and Detection, Working Together

To help MSPs and IT teams, DNSFilter and Blumira have introduced a native integration built on Blumira’s recently launched HTTP ingest capability.  The goal is to combine prevention at the DNS layer with broader detection and investigation across the rest of the environment.

The idea is to block as much malicious activity as possible before it reaches a user, then preserve enough context to understand what happened before and after the block.

DNSFilter handles the first part by using domain intelligence and predictive analysis to stop users and devices from reaching known or suspected malicious destinations.  Blumira handles the second part by ingesting DNS activity from DNSFilter — both blocked and allowed requests — as additional detection signal and investigative context inside its security operations platform.

The blocked requests piece is important because a successful block is not necessarily the end of an incident.  A blocked request may indicate that a user clicked a phishing link, malware attempted to contact command-and-control infrastructure, or several endpoints are exhibiting similar behavior.  Retaining that activity inside Blumira gives security teams a way to correlate the DNS event with endpoint, identity, cloud, and other security telemetry, rather than treating it as a closed case.

It also helps address one of the weaknesses of fragmented security environments.  Endpoints and identity remain common entry points, so many security solutions concentrate heavily on those layers.  But, attacks rarely stay confined to a single system and may move from an initial credential compromise into cloud applications, connected services or internal infrastructure before data is stolen and traces are removed

DNS data can provide connective context, showing which systems attempted to reach suspicious infrastructure and when that activity occurred.  When combined with the other telemetry already flowing into Blumira, it can help security teams see how an incident is progressing across the environment rather than responding to each alert independently.

Let’s be clear:  the integration is not a substitute for endpoint, identity, or cloud controls, but it reduces the gap between a preventive tool and the systems responsible for investigation.

Speed and Context Matter

DNSFilter’s report provides useful context for why that gap is becoming more consequential.

The company processes more than 200 billion DNS queries each day and blocks roughly 7% of that traffic across its security and content-filtering policies.  During the reporting period, it processed more than 52 trillion queries and found that identified threat activity grew more than 30% in volume and sophistication.

As noted earlier, an interesting finding is that newly created domains represented more than 65% of all unique threat domains on DNSFilter’s network and appeared more than six times as often as the next-largest category, malware.  These domains tend to receive relatively little traffic because they are often created for narrow campaigns, used briefly and then abandoned or recycled into new infrastructure.  That makes them difficult to catch with defenses that depend on an established history or previously observed reputation.

Hee's how that strategy works in practice.  DNSFilter tracked more than 11,000 subdomains associated with the Tycoon 2FA phishing-as-a-service operation.  Most received only a handful of queries, evidence of infrastructure designed to be short-lived and low-profile.  In another case, a fake CAPTCHA connected to Lumma Stealer persuaded roughly 17% of the users who encountered it to follow instructions that triggered an attempted malware delivery.

The commonality is not simply the presence of a malicious domain, but the use of temporary infrastructure, user interaction, and multiple steps to produce an attack.  DNS-layer prevention can stop an important part of that sequence, but a blocked or allowed request may represent only one moment in a larger campaign.

That’s where Blumira’s upcoming research is relevant.  If attacks increasingly involve several systems and MITRE ATT&CK stages, the value of DNS telemetry is not limited to deciding whether a website should be accessible.  It can also help establish chronology, identify affected systems and reveal repeated behavior that might otherwise look unrelated.

We already know the incidents are happening faster than ever and the time between a threat appearing and damage being caused is shrinking.  Static intelligence alone cannot keep pace with infrastructure that may not have existed the previous day, while detection tools operating without DNS context may miss an early indicator of how an incident began or spread.

The point of the Blumira-DNSFilter integration is not that it eliminates the need for broader security controls.  Rather, it’s that preventive DNS intelligence is an important part of the detection and investigation process.  For small IT teams and MSPs working with many clients, reducing the gaps between tools is important to their ability to defend effectively.



Get stories like this delivered straight to your inbox. [Free eNews Subscription]

Group Editorial Director

SHARE THIS ARTICLE
Related Articles

Why DNS Security and Threat Detection Need to Work Together

By: Erik Linask    7/21/2026

DNSFilter and Blumira have launched a native integration that combines predictive DNS threat blocking with continuous security monitoring to help orga…

Read More

From Generic VSaaS to Vertical Expertise: A Growth Strategy for MSPs

By: Erik Linask    7/15/2026

MSPs can build tailored VSaaS offerings for healthcare, education, logistics, and other industries by combining flexible VMS platforms with vertical-s…

Read More

Why AI Spend Management Could Become the Next MSP Service Opportunity

By: Erik Linask    7/14/2026

As AI costs rise, businesses need visibility into token usage and budget risk, which creates a potential new AI cost-governance revenue opportunity fo…

Read More

The Next SOC Shift Is Here: Autonomous Identity Response for MSPs

By: Erik Linask    7/8/2026

Blackpoint Cyber's new AI SOC Agent for Identity Threat Detection and Response gives MSPs an autonomous, human-guided way to contain high-confidence c…

Read More

Identity Is the New Perimeter and MSPs Are on the Front Line

By: Erik Linask    7/8/2026

Barracuda's acquisition of Evo Security expands BarracudaONE with MSP-focused IAM and PAM capabilities, highlighting how identity resilience is becomi…

Read More