Windows DNS queries containing Diamond Sleet–related domains

Alerts on Windows DNS queries for QueryName values containing specific Diamond Sleet–related domains.

FreeReviewedSigma · High · v5
Product
windows
Category
dns_query
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-10-24
Updated
2026-07-31

What it detects

This rule matches DNS queries on Windows where the query name contains any of four hard-coded domains tied to Diamond Sleet indicators. Attackers may use domain infrastructure for command-and-control or staging, so these specific lookups can provide early detection signals. The detection relies on DNS query telemetry that includes the queried name (QueryName) and evaluates substring matches.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.