Suspicious connections
Find devices communicating with external destinations that are new, unusual, or unexpected for your business.
Practical cybersecurity visibility
Icefall uses security signals from compatible network infrastructure to uncover suspicious destinations, changing behaviour, and evidence for later investigation.
Request a free consultationSecurity evidence when you need it
Security investigations often begin after a user notices something, a provider shares new threat information, or a business system behaves differently. Retained network records preserve evidence that would otherwise disappear.
Scheduled review doesn't replace real-time security controls. It adds another opportunity to find persistent patterns, create a baseline, and investigate events after the initial activity.
Find devices communicating with external destinations that are new, unusual, or unexpected for your business.
Recognize domains associated with phishing concerns, newly discovered threats, or activity that deserves investigation.
See when devices, destinations, traffic volume, or timing begin to differ from the patterns normally visible in your business.
Look back when an employee reports phishing, a provider issues a warning, or an investigation begins after the original event.
241-day average breach lifecycle
IBM reports that identifying and containing an active breach takes 241 days on average across industries. Mandiant separately reported a 14-day global median from compromise to discovery in its 2025 investigations, rising to 122 days for cyber-espionage and North Korean IT-worker incidents.
Recognize suspicious destinations
Website and service names add important context to otherwise technical network activity. They become more useful when combined with connection timing and information about the device involved.
MITRE ATT&CK documents how adversaries may also abuse DNS for command-and-control and tunnelling. Unusual DNS activity requires further investigation.
Common security situations
Phishing follow-up
01Retained DNS and connection records may show which device looked up or contacted the reported domain and when. That can help your IT team scope the follow-up instead of relying only on memory.
Double-check: The records can't prove that credentials were entered or show the encrypted page contents.
New threat information
02Historical DNS records can be searched for earlier lookups, while connection records may help identify the internal addresses involved and the first and last activity visible in the retained data.
Double-check: A lookup or connection is evidence to investigate—not proof that a device was compromised.
Repeated communication
03A repeated, low-volume pattern can stand out in a weekly review even when each individual connection looks ordinary. Your IT team can then examine the device and the software responsible.
Double-check: Legitimate software updates and cloud services can create similar patterns.
Unexpected data movement
04Connection and flow records may reveal an unusual increase in data sent to a cloud host or external network, providing a time window and source device for the client to investigate.
Double-check: The cause might be a backup, update, remote worker, or another authorized business process.
DNS anomalies
05High-frequency failures, long encoded-looking subdomains, or repeated TXT queries can justify closer review. Attackers can abuse DNS for command-and-control or tunnelling, but unusual DNS also has many benign causes.
Double-check: Endpoint investigation is normally required to determine which process generated the requests.
Unknown equipment
06When DHCP or network identity context is available, the report can highlight a newly observed printer, camera, personal device, or other system and the destinations it begins using.
Double-check: Your IT team should confirm whether the device and its activity are authorized.
Wider exposure
07A shared destination appearing across multiple devices can show that a concern is broader than one workstation. The records can identify the systems involved, when activity began, and whether the pattern is continuing.
Double-check: Advertising networks, shared cloud services, and legitimate business software can also create common destinations.
Remote access activity
08When compatible VPN or network security records are available, the review can connect remote-access activity to a source address, account event, time, and internal destination for your IT team to verify.
Double-check: An unfamiliar source address or location doesn't prove that an account was compromised.
What you receive
Weekly security review
Monthly risk trends
If clearly serious activity is discovered during a scheduled review, Icefall can notify the designated contact promptly. The service doesn't provide continuous monitoring, guaranteed detection, or emergency incident response.
Service limitations
Network logs normally show metadata rather than encrypted content. They may identify a device, destination, time, protocol, and traffic volume, but they usually can't show what a user typed, which file was opened, or which endpoint process made the connection.
Findings are presented with context and limitations so the your IT team can decide what requires endpoint investigation, account review, blocking, or another response.