Sigma Rule Library

Log source category

dns_query log source Sigma rules

29 Sigma detection rules in the library use the dns_query log source, mostly on windows. The dns_query category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.

29 rules

Products

Severity