Log source category
dns_query log source Sigma rules
29 Sigma detection rules in the library use the dns_query log source, mostly on windows. The dns_query category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Suspicious Cobalt Strike DNS Beaconing - Sysmon
criticalDetects a program that invoked suspicious DNS queries known from Cobalt Strike beacons
windows
Diamond Sleet APT DNS Communication Indicators
highDetects DNS queries related to Diamond Sleet APT activity
windows
DNS HybridConnectionManager Service Bus
highDetects Azure Hybrid Connection Manager services querying the Azure service bus service
windows
DNS Query by Finger Utility
highDetects DNS queries made by the finger utility, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such DNS queries can also help identify potential malicious infrastructure used by threat actors for command and control (C2) communication.
windows
DNS Query for Anonfiles.com Domain - Sysmon
highDetects DNS queries for "anonfiles.com", which is an anonymous file upload platform often used for malicious purposes
windows
DNS Query To Katz Stealer Domains
highDetects DNS queries to domains associated with Katz Stealer malware. Katz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems. In Enterprise environments, DNS queries to these domains may indicate potential malicious activity or compromise.
windows
DNS Query Tor .Onion Address - Sysmon
highDetects DNS queries to an ".onion" address related to Tor routing networks
windows
DPRK Threat Actor - C2 Communication DNS Indicators
highDetects DNS queries for C2 domains used by DPRK Threat actors.
windows
Potential Compromised 3CXDesktopApp Beaconing Activity - DNS
highDetects potential beaconing activity to domains related to 3CX 3CXDesktopApp compromise
windows
Potential SocGholish Second Stage C2 DNS Query
highDetects a DNS query initiated from a "wscript" process for domains matching a specific pattern that was seen being used by SocGholish for its Command and Control traffic
windows
Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing
highDetects DNS queries containing patterns associated with Kerberos coercion attacks via DNS object spoofing. The pattern "1UWhRCAAAAA..BAAAA" is a base64-encoded signature that corresponds to a marshaled CREDENTIAL_TARGET_INFORMATION structure. Attackers can use this technique to coerce authentication from victim systems to attacker-controlled hosts. It is one of the strong indicators of a Kerberos coercion attack, where adversaries manipulate DNS records to spoof Service Principal Names (SPNs) and redirect authentication requests like CVE-2025-33073.
windows
AppX Package Installation Attempts Via AppInstaller.EXE
mediumDetects DNS queries made by "AppInstaller.EXE". The AppInstaller is the default handler for the "ms-appinstaller" URI. It attempts to load/install a package from the referenced URL
windows
Cloudflared Tunnels Related DNS Requests
mediumDetects DNS requests to Cloudflared tunnels domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows
DNS Query Request By Regsvr32.EXE
mediumDetects DNS queries initiated by "Regsvr32.exe"
windows
DNS Query To AzureWebsites.NET By Non-Browser Process
mediumDetects a DNS query by a non browser process on the system to "azurewebsites.net". The latter was often used by threat actors as a malware hosting and exfiltration site.
windows
DNS Query To Common Malware Hosting and Shortener Services
mediumDetects DNS queries to domains commonly used by threat actors to host malware payloads or redirect through URL shorteners. These include platforms like Cloudflare Workers, TryCloudflare, InfinityFree, and URL shorteners such as tinyurl and lihi.cc. Such DNS activity can indicate potential delivery or command-and-control communication attempts.
windows
DNS Query To Devtunnels Domain
mediumDetects DNS query requests to Devtunnels domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows
DNS Query To MEGA Hosting Website
mediumDetects DNS queries for subdomains related to MEGA sharing website
windows
DNS Query To Remote Access Software Domain From Non-Browser App
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
DNS Query To Visual Studio Code Tunnels Domain
mediumDetects DNS query requests to Visual Studio Code tunnel domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows
Notepad++ Updater DNS Query to Uncommon Domains
mediumDetects when the Notepad++ updater (gup.exe) makes DNS queries to domains that are not part of the known legitimate update infrastructure. This could indicate potential exploitation of the updater mechanism or suspicious network activity that warrants further investigation.
windows
Suspicious DNS Query for IP Lookup Service APIs
mediumDetects DNS queries for IP lookup services such as "api.ipify.org" originating from a non browser process.
windows
TanStack Supply-Chain Attack DNS Indicators
mediumDetects DNS queries to attacker-controlled infrastructure used by the Mini Shai-Hulud campaign targeting TanStack npm packages along with other packages such as mistralai, uipath and so on. The domain git-tanstack.com (registered May 9, 2026) hosted secondary payloads including transformers.pyz. The filev2.getsession.org endpoint was used for credential exfiltration via the Session protocol.
windows
TeamViewer Domain Query By Non-TeamViewer Application
mediumDetects DNS queries to a TeamViewer domain only resolved by a TeamViewer client by an image that isn't named TeamViewer (sometimes used by threat actors for obfuscation)
windows
DNS Query Request By QuickAssist.EXE
lowDetects DNS queries initiated by "QuickAssist.exe" to Microsoft Quick Assist primary endpoint that is used to establish a session.
windows
DNS Query Request To OneLaunch Update Service
lowDetects DNS query requests to "update.onelaunch.com". This domain is associated with the OneLaunch adware application. When the OneLaunch application is installed it will attempt to get updates from this domain.
windows
DNS Query To Ufile.io
lowDetects DNS queries to "ufile.io", which was seen abused by malware and threat actors as a method for data exfiltration
windows
DNS Request From Windows Script Host
lowDetects unusual domain resolutions originating from CScript/WScript that can identify malicious javascript files executing in an environment, often as a result from a phishing or watering hole attack.
windows
DNS Server Discovery Via LDAP Query
lowDetects DNS server discovery via LDAP query requests from uncommon applications
windows