Windows Sysmon Detect DNS Queries for .onion and Tor Gateway/Proxy Domains
Alerts when Windows Sysmon DNS queries target .onion or Tor gateway/proxy-related domain suffixes.
FreeUnreviewedSigmahighv1
windows-sysmon-detect-dns-queries-for-onion-and-tor-gateway-proxy-domains-b55ca2a3
title: Windows Sysmon Detect DNS Queries for .onion and Tor Gateway/Proxy Domains
id: 251185c0-8dc7-4f56-b3e7-3bb452345a13
related:
- id: 8384bd26-bde6-4da9-8e5d-4174a7a47ca2
type: similar
- id: a8322756-015c-42e7-afb1-436e85ed3ff5
type: similar
- id: b55ca2a3-7cff-4dda-8bdd-c7bfa63bf544
type: derived
status: test
description: This rule flags DNS query events where the queried name ends with common .onion hidden service domains or known Tor gateway/proxy-related domains. Such traffic is often associated with attacker command-and-control infrastructure or anonymity-oriented routing. The detection relies on Windows Sysmon DNS query telemetry, specifically the QueryName suffix observed in DNSQuery events.
references:
- https://www.logpoint.com/en/blog/detecting-tor-use-with-logpoint/
- https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/ASimDNS/imDNS_TorProxies.yaml
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/dns_query/dns_query_win_tor_onion_domain_query.yml
author: frack113, Huntrule Team
date: 2022-02-20
modified: 2025-09-12
tags:
- attack.command-and-control
- attack.t1090.003
logsource:
product: windows
category: dns_query
detection:
selection:
QueryName|endswith:
- .hiddenservice.net
- .onion.ca
- .onion.cab
- .onion.casa
- .onion.city
- .onion.direct
- .onion.dog
- .onion.glass
- .onion.gq
- .onion.ink
- .onion.it
- .onion.link
- .onion.lt
- .onion.lu
- .onion.nu
- .onion.pet
- .onion.plus
- .onion.rip
- .onion.sh
- .onion.to
- .onion.top
- .onion
- .s1.tor-gateways.de
- .s2.tor-gateways.de
- .s3.tor-gateways.de
- .s4.tor-gateways.de
- .s5.tor-gateways.de
- .t2w.pw
- .tor2web.ae.org
- .tor2web.blutmagie.de
- .tor2web.com
- .tor2web.fi
- .tor2web.io
- .tor2web.org
- .tor2web.xyz
- .torlink.co
condition: selection
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags DNS query events where the queried name ends with common .onion hidden service domains or known Tor gateway/proxy-related domains. Such traffic is often associated with attacker command-and-control infrastructure or anonymity-oriented routing. The detection relies on Windows Sysmon DNS query telemetry, specifically the QueryName suffix observed in DNSQuery events.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.