Zeek DNS queries to Tor proxy and onion domain indicators

Alerts on Zeek DNS queries for Tor proxy and onion domain indicators tied to possible anonymized activity.

FreeUnreviewedSigmamediumv1
title: Zeek DNS queries to Tor proxy and onion domain indicators
id: 27c6663f-7f96-49b4-8596-e391d65284f6
related:
  - id: b55ca2a3-7cff-4dda-8bdd-c7bfa63bf544
    type: similar
  - id: 8384bd26-bde6-4da9-8e5d-4174a7a47ca2
    type: similar
  - id: a8322756-015c-42e7-afb1-436e85ed3ff5
    type: derived
status: test
description: This rule flags DNS lookup events where the queried domain matches known Tor proxy and onion-related domain indicators, including .onion and specific Tor gateway and Tor2web/torlink patterns. Such lookups can indicate anonymization or proxy use during command-and-control, data access, or exfiltration workflows. It relies on Zeek DNS telemetry, specifically DNS query names observed in network logs.
references:
  - https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/ASimDNS/imDNS_TorProxies.yaml
  - https://github.com/SigmaHQ/sigma/blob/master/rules/network/zeek/zeek_dns_torproxy.yml
author: Saw Winn Naung , Azure-Sentinel, Huntrule Team
date: 2021-08-15
modified: 2025-09-12
tags:
  - attack.exfiltration
  - attack.t1048
logsource:
  service: dns
  product: zeek
detection:
  selection:
    query|endswith:
      - .hiddenservice.net
      - .onion.ca
      - .onion.cab
      - .onion.casa
      - .onion.city
      - .onion.direct
      - .onion.dog
      - .onion.glass
      - .onion.gq
      - .onion.guide
      - .onion.in.net
      - .onion.ink
      - .onion.it
      - .onion.link
      - .onion.lt
      - .onion.lu
      - .onion.ly
      - .onion.mn
      - .onion.network
      - .onion.nu
      - .onion.pet
      - .onion.plus
      - .onion.pt
      - .onion.pw
      - .onion.rip
      - .onion.sh
      - .onion.si
      - .onion.to
      - .onion.top
      - .onion.ws
      - .onion
      - .s1.tor-gateways.de
      - .s2.tor-gateways.de
      - .s3.tor-gateways.de
      - .s4.tor-gateways.de
      - .s5.tor-gateways.de
      - .t2w.pw
      - .tor2web.ae.org
      - .tor2web.blutmagie.de
      - .tor2web.com
      - .tor2web.fi
      - .tor2web.io
      - .tor2web.org
      - .tor2web.xyz
      - .torlink.co
  condition: selection
falsepositives:
  - Unknown
level: medium
license: DRL-1.1

What it detects

This rule flags DNS lookup events where the queried domain matches known Tor proxy and onion-related domain indicators, including .onion and specific Tor gateway and Tor2web/torlink patterns. Such lookups can indicate anonymization or proxy use during command-and-control, data access, or exfiltration workflows. It relies on Zeek DNS telemetry, specifically DNS query names observed in network logs.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.