Log source category
dns log source Sigma rules
11 Sigma detection rules in the library use the dns log source. The dns category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Cobalt Strike DNS Beaconing
criticalDetects suspicious DNS queries known from Cobalt Strike beacons
Axios NPM Compromise Malicious C2 Domain DNS Query
highDetects DNS queries for the malicious C2 domain associated with the plain-crypto-js/Axios npm package supply chain compromise. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. This detection detects endpoints attempting to resolve the attacker's C2 domain (sfrclak.com) used for command and control communication.
DNS Query to External Service Interaction Domains
highDetects DNS queries to well-known out-of-band application security testing (OAST) and callback domains. These services (e.g. Burp Collaborator, interactsh, canarytokens, dnslog.cn) are used by security researchers and attackers alike to confirm blind vulnerabilities such as SSRF, XXE, blind RCE, and Log4Shell-style injections, where the exploit payload triggers an external DNS lookup to a controlled domain. A detection indicates that a host on your network resolved one of these domains, which may mean: (1) an attacker is actively probing or exploiting a vulnerable service and using the callback to confirm code execution or data exfiltration, (2) a security scanner (e.g. Nuclei, Gobies) is running against internal targets. Investigate the source host, the full DNS query string (the unique subdomain prefix encodes the callback session), and any concurrent outbound connections or process activity to determine intent.
DNS Query To Katz Stealer Domains - Network
highDetects DNS queries to domains associated with Katz Stealer malware. Katz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems. In Enterprise environments, DNS queries to these domains may indicate potential malicious activity or compromise.
DNS TXT Answer with Possible Execution Strings
highDetects strings used in command execution in DNS TXT Answer
Monero Crypto Coin Mining Pool Lookup
highDetects suspicious DNS queries to Monero mining pools
Potential Operation Triangulation C2 Beaconing Activity - DNS
highDetects potential beaconing activity to domains used in 0day attacks on iOS devices and revealed by Kaspersky and the FSB
Wannacry Killswitch Domain
highDetects wannacry killswitch domain dns queries
Low Reputation Effective Top-Level Domain (eTLD)
mediumDetects DNS queries to domains within known low reputation eTLDs. This rule uses AlphaSOC's threat intelligence data and is updated on a monthly basis.
Suspicious DNS Query with B64 Encoded String
mediumDetects suspicious DNS queries using base64 encoding
Telegram Bot API Request
mediumDetects suspicious DNS queries to api.telegram.org used by Telegram Bots of any kind