Windows DNS Client Query for Tor .onion or Tor2web/Hidden Service Domains

Alerts on Windows DNS queries resolving .onion and related Tor/hidden-service domains.

FreeUnreviewedSigmahighv1
title: Windows DNS Client Query for Tor .onion or Tor2web/Hidden Service Domains
id: 363dfe7f-6101-4755-aed8-c113d73d59ab
related:
  - id: b55ca2a3-7cff-4dda-8bdd-c7bfa63bf544
    type: similar
  - id: a8322756-015c-42e7-afb1-436e85ed3ff5
    type: similar
  - id: 8384bd26-bde6-4da9-8e5d-4174a7a47ca2
    type: derived
status: test
description: This rule flags Windows DNS Client events where the DNS query name ends with common Tor/hidden-service related domains, including .onion and .hiddenservice.net, as well as several Tor2web-related host patterns. Attackers may use DNS resolution of these domains to reach Tor-routed infrastructure for command-and-control or anonymized access. It relies on Microsoft-Windows-DNS Client operational telemetry capturing EventID 3008 and the queried name suffix.
references:
  - https://www.logpoint.com/en/blog/detecting-tor-use-with-logpoint/
  - https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/ASimDNS/imDNS_TorProxies.yaml
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/dns_client/win_dns_client_tor_onion.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-02-20
modified: 2025-09-12
tags:
  - attack.command-and-control
  - attack.t1090.003
logsource:
  product: windows
  service: dns-client
  definition: "Requirements: Microsoft-Windows-DNS Client Events/Operational Event Log must be enabled/collected in order to receive the events."
detection:
  selection:
    EventID: 3008
    QueryName|endswith:
      - .hiddenservice.net
      - .onion.ca
      - .onion.cab
      - .onion.casa
      - .onion.city
      - .onion.direct
      - .onion.dog
      - .onion.glass
      - .onion.gq
      - .onion.guide
      - .onion.in.net
      - .onion.ink
      - .onion.it
      - .onion.link
      - .onion.lt
      - .onion.lu
      - .onion.ly
      - .onion.mn
      - .onion.network
      - .onion.nu
      - .onion.pet
      - .onion.plus
      - .onion.pt
      - .onion.pw
      - .onion.rip
      - .onion.sh
      - .onion.si
      - .onion.to
      - .onion.top
      - .onion.ws
      - .onion
      - .s1.tor-gateways.de
      - .s2.tor-gateways.de
      - .s3.tor-gateways.de
      - .s4.tor-gateways.de
      - .s5.tor-gateways.de
      - .t2w.pw
      - .tor2web.ae.org
      - .tor2web.blutmagie.de
      - .tor2web.com
      - .tor2web.fi
      - .tor2web.io
      - .tor2web.org
      - .tor2web.xyz
      - .torlink.co
  condition: selection
falsepositives:
  - Unlikely
level: high
license: DRL-1.1

What it detects

This rule flags Windows DNS Client events where the DNS query name ends with common Tor/hidden-service related domains, including .onion and .hiddenservice.net, as well as several Tor2web-related host patterns. Attackers may use DNS resolution of these domains to reach Tor-routed infrastructure for command-and-control or anonymized access. It relies on Microsoft-Windows-DNS Client operational telemetry capturing EventID 3008 and the queried name suffix.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.