Possible DNS Server Enumeration Through LDAP Query (via dns_query)
This rule detects DNS server discovery via LDAP query requests from uncommon applications
SigmalowWindowsv1
sigma
possible-dns-server-enumeration-through-ldap-query-via-dns-query
title: Possible DNS Server Enumeration Through LDAP Query (via dns_query)
id: 4e7fa803-3668-5735-ad5d-14f6d51e4cf0
status: stable
description: This rule detects DNS server discovery via LDAP query requests from uncommon applications
references:
- https://attack.mitre.org/techniques/T1482/
- https://github.com/redcanaryco/atomic-red-team/blob/980f3f83fd81f37c1ca9c02dccfd1c3d9f9d0841/atomics/T1016/T1016.md#atomic-test-9---dns-server-discovery-using-nslookup
- https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/7fcdce70-5205-44d6-9c3a-260e616a2f04
author: Huntrule Team
date: 2026-01-17
tags:
- attack.discovery
- attack.t1482
logsource:
product: windows
category: dns_query
detection:
selection:
QueryName|startswith: '_ldap.'
filter_main_generic:
Image|contains:
- ':\Program Files\'
- ':\Program Files (x86)\'
- ':\Windows\'
filter_main_defender:
Image|contains: ':\ProgramData\Microsoft\Windows Defender\Platform\'
Image|endswith: '\MsMpEng.exe'
filter_main_unknown:
Image: '<unknown process>'
filter_optional_azure:
Image|startswith: 'C:\WindowsAzure\GuestAgent'
filter_main_null:
Image:
filter_optional_browsers:
Image|endswith:
- '\chrome.exe'
- '\firefox.exe'
- '\opera.exe'
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unknown
level: low
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.