Windows dnscmd.exe DNS Zone and Record Enumeration Command Execution

Flags dnscmd.exe executions that enumerate DNS zones/records via process creation command-line parameters.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
@gott_cyber (SigmaHQ), DRL 1.1
Published
2022-07-31
Updated
2026-07-31

What it detects

This rule identifies process executions of dnscmd.exe where the command line contains DNS enumeration flags such as /enumrecords, /enumzones, /ZonePrint, or /info. Attackers and administrators can use dnscmd to discover DNS zone contents and configuration, which supports further targeting and internal recon. The detection relies on Windows process creation telemetry capturing the executable path and command-line arguments.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.