Windows DNS Client Query for Tor .onion or Tor2web/Hidden Service Domains
Alerts on Windows DNS queries resolving .onion and related Tor/hidden-service domains.
FreeUnreviewedSigmahighv1
windows-dns-client-query-for-tor-onion-or-tor2web-hidden-service-domains-8384bd26
title: Windows DNS Client Query for Tor .onion or Tor2web/Hidden Service Domains
id: 363dfe7f-6101-4755-aed8-c113d73d59ab
related:
- id: b55ca2a3-7cff-4dda-8bdd-c7bfa63bf544
type: similar
- id: a8322756-015c-42e7-afb1-436e85ed3ff5
type: similar
- id: 8384bd26-bde6-4da9-8e5d-4174a7a47ca2
type: derived
status: test
description: This rule flags Windows DNS Client events where the DNS query name ends with common Tor/hidden-service related domains, including .onion and .hiddenservice.net, as well as several Tor2web-related host patterns. Attackers may use DNS resolution of these domains to reach Tor-routed infrastructure for command-and-control or anonymized access. It relies on Microsoft-Windows-DNS Client operational telemetry capturing EventID 3008 and the queried name suffix.
references:
- https://www.logpoint.com/en/blog/detecting-tor-use-with-logpoint/
- https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/ASimDNS/imDNS_TorProxies.yaml
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/dns_client/win_dns_client_tor_onion.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-02-20
modified: 2025-09-12
tags:
- attack.command-and-control
- attack.t1090.003
logsource:
product: windows
service: dns-client
definition: "Requirements: Microsoft-Windows-DNS Client Events/Operational Event Log must be enabled/collected in order to receive the events."
detection:
selection:
EventID: 3008
QueryName|endswith:
- .hiddenservice.net
- .onion.ca
- .onion.cab
- .onion.casa
- .onion.city
- .onion.direct
- .onion.dog
- .onion.glass
- .onion.gq
- .onion.guide
- .onion.in.net
- .onion.ink
- .onion.it
- .onion.link
- .onion.lt
- .onion.lu
- .onion.ly
- .onion.mn
- .onion.network
- .onion.nu
- .onion.pet
- .onion.plus
- .onion.pt
- .onion.pw
- .onion.rip
- .onion.sh
- .onion.si
- .onion.to
- .onion.top
- .onion.ws
- .onion
- .s1.tor-gateways.de
- .s2.tor-gateways.de
- .s3.tor-gateways.de
- .s4.tor-gateways.de
- .s5.tor-gateways.de
- .t2w.pw
- .tor2web.ae.org
- .tor2web.blutmagie.de
- .tor2web.com
- .tor2web.fi
- .tor2web.io
- .tor2web.org
- .tor2web.xyz
- .torlink.co
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1
What it detects
This rule flags Windows DNS Client events where the DNS query name ends with common Tor/hidden-service related domains, including .onion and .hiddenservice.net, as well as several Tor2web-related host patterns. Attackers may use DNS resolution of these domains to reach Tor-routed infrastructure for command-and-control or anonymized access. It relies on Microsoft-Windows-DNS Client operational telemetry capturing EventID 3008 and the queried name suffix.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.