Indicators of Compromise of Report

Hey All,

I have a large list of known bad IPs and Bad Domain Names.  Is there a way to import this list into ESM and Alert if any tracffic is going to these IPs or if anything is trying to do a DNS lookup on the known Bad Domain Names?

Thanks,

Eric

Tags: