Windows Sysmon Detect DNS Queries for .onion and Tor Gateway/Proxy Domains

Alerts when Windows Sysmon DNS queries target .onion or Tor gateway/proxy-related domain suffixes.

FreeUnreviewedSigmahighv1
title: Windows Sysmon Detect DNS Queries for .onion and Tor Gateway/Proxy Domains
id: 251185c0-8dc7-4f56-b3e7-3bb452345a13
related:
  - id: 8384bd26-bde6-4da9-8e5d-4174a7a47ca2
    type: similar
  - id: a8322756-015c-42e7-afb1-436e85ed3ff5
    type: similar
  - id: b55ca2a3-7cff-4dda-8bdd-c7bfa63bf544
    type: derived
status: test
description: This rule flags DNS query events where the queried name ends with common .onion hidden service domains or known Tor gateway/proxy-related domains. Such traffic is often associated with attacker command-and-control infrastructure or anonymity-oriented routing. The detection relies on Windows Sysmon DNS query telemetry, specifically the QueryName suffix observed in DNSQuery events.
references:
  - https://www.logpoint.com/en/blog/detecting-tor-use-with-logpoint/
  - https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/ASimDNS/imDNS_TorProxies.yaml
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/dns_query/dns_query_win_tor_onion_domain_query.yml
author: frack113, Huntrule Team
date: 2022-02-20
modified: 2025-09-12
tags:
  - attack.command-and-control
  - attack.t1090.003
logsource:
  product: windows
  category: dns_query
detection:
  selection:
    QueryName|endswith:
      - .hiddenservice.net
      - .onion.ca
      - .onion.cab
      - .onion.casa
      - .onion.city
      - .onion.direct
      - .onion.dog
      - .onion.glass
      - .onion.gq
      - .onion.ink
      - .onion.it
      - .onion.link
      - .onion.lt
      - .onion.lu
      - .onion.nu
      - .onion.pet
      - .onion.plus
      - .onion.rip
      - .onion.sh
      - .onion.to
      - .onion.top
      - .onion
      - .s1.tor-gateways.de
      - .s2.tor-gateways.de
      - .s3.tor-gateways.de
      - .s4.tor-gateways.de
      - .s5.tor-gateways.de
      - .t2w.pw
      - .tor2web.ae.org
      - .tor2web.blutmagie.de
      - .tor2web.com
      - .tor2web.fi
      - .tor2web.io
      - .tor2web.org
      - .tor2web.xyz
      - .torlink.co
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule flags DNS query events where the queried name ends with common .onion hidden service domains or known Tor gateway/proxy-related domains. Such traffic is often associated with attacker command-and-control infrastructure or anonymity-oriented routing. The detection relies on Windows Sysmon DNS query telemetry, specifically the QueryName suffix observed in DNSQuery events.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.