Windows DNS Server: Failed DNS Zone Transfer Requests (Event ID 6004)

Alerts on Windows DNS Server Event ID 6004 indicating a failed DNS zone transfer request for a non-existent or non-authoritative zone.

FreeReviewedSigma · Medium · v2
Product
windows
Service
dns-server
Author
Zach Mathis (SigmaHQ), DRL 1.1
Published
2023-05-24
Updated
2026-07-31

ATT&CK techniques

Recon
  1. Resource Dev

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Windows DNS Server events where a DNS zone transfer request fails for a non-existent or non-authoritative zone. Attackers may probe DNS infrastructure with zone transfer attempts to enumerate DNS records, even if authorization is missing. It relies on DNS Server service telemetry for Event ID 6004, including the source requesting system and the target zone name.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.