So update, Ivanti is doing it. Our team that manages that has seen some turnover and man the prod policy is in rough shape. So we open Wireshark, refresh google or something after flushing dns, we get like 10 packets maybe. Re-enable Ivanti App manager and it just FLOODs with DNS requests. Our networking team said we get like 60k "malformed" requests per proxy per day from this traffic.