Category
Business Management
Built by
Beam.ai
Flag blocked domains and DNS threat events across DNSFilter policies, automating routine notices for known threats and routing unclear or repeated incidents to a human.
Threat Domain Blocking
A Beam agent reads the domains DNSFilter has blocked across a customer's networks and checks each block against the categories the customer has approved for automatic action, such as known malware or phishing domains. Where the category is clear, the agent confirms the block stands and notes it in an incident record without further action. A blocked domain tied to a business application, a repeated request from the same user to unblock it, or a category outside the approved list is routed to a human to decide whether the block should stay or be lifted.
Policy Updates Across Networks
A Beam agent reads a request to change a DNSFilter policy, such as adding a domain to an allow list for a specific network or user group, and checks it against the criteria a customer has set for routine changes. Where the request fits, the agent updates the policy and notes who requested it and when. A request touching a policy shared across multiple networks, an unusual domain category, or a change with no clear business reason attached is held back and routed to a human before the policy is changed.
Threat Log Handling
A Beam agent reads DNSFilter's threat activity log on a schedule and groups events by domain, category, and the network or device involved, looking for a pattern a customer has asked to be told about, such as repeated attempts from one device. Where a pattern matches an approved rule, the agent adds a note to an incident tracker so the security team has context without reading the raw log. A pattern involving a large volume of attempts, a device outside the expected network, or a category the agent has not seen before is routed to a human right away.







