Zeek DNS queries to Tor proxy and onion domain indicators
Alerts on Zeek DNS queries for Tor proxy and onion domain indicators tied to possible anonymized activity.
FreeUnreviewedSigmamediumv1
zeek-dns-queries-to-tor-proxy-and-onion-domain-indicators-a8322756
title: Zeek DNS queries to Tor proxy and onion domain indicators
id: 27c6663f-7f96-49b4-8596-e391d65284f6
related:
- id: b55ca2a3-7cff-4dda-8bdd-c7bfa63bf544
type: similar
- id: 8384bd26-bde6-4da9-8e5d-4174a7a47ca2
type: similar
- id: a8322756-015c-42e7-afb1-436e85ed3ff5
type: derived
status: test
description: This rule flags DNS lookup events where the queried domain matches known Tor proxy and onion-related domain indicators, including .onion and specific Tor gateway and Tor2web/torlink patterns. Such lookups can indicate anonymization or proxy use during command-and-control, data access, or exfiltration workflows. It relies on Zeek DNS telemetry, specifically DNS query names observed in network logs.
references:
- https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/ASimDNS/imDNS_TorProxies.yaml
- https://github.com/SigmaHQ/sigma/blob/master/rules/network/zeek/zeek_dns_torproxy.yml
author: Saw Winn Naung , Azure-Sentinel, Huntrule Team
date: 2021-08-15
modified: 2025-09-12
tags:
- attack.exfiltration
- attack.t1048
logsource:
service: dns
product: zeek
detection:
selection:
query|endswith:
- .hiddenservice.net
- .onion.ca
- .onion.cab
- .onion.casa
- .onion.city
- .onion.direct
- .onion.dog
- .onion.glass
- .onion.gq
- .onion.guide
- .onion.in.net
- .onion.ink
- .onion.it
- .onion.link
- .onion.lt
- .onion.lu
- .onion.ly
- .onion.mn
- .onion.network
- .onion.nu
- .onion.pet
- .onion.plus
- .onion.pt
- .onion.pw
- .onion.rip
- .onion.sh
- .onion.si
- .onion.to
- .onion.top
- .onion.ws
- .onion
- .s1.tor-gateways.de
- .s2.tor-gateways.de
- .s3.tor-gateways.de
- .s4.tor-gateways.de
- .s5.tor-gateways.de
- .t2w.pw
- .tor2web.ae.org
- .tor2web.blutmagie.de
- .tor2web.com
- .tor2web.fi
- .tor2web.io
- .tor2web.org
- .tor2web.xyz
- .torlink.co
condition: selection
falsepositives:
- Unknown
level: medium
license: DRL-1.1
What it detects
This rule flags DNS lookup events where the queried domain matches known Tor proxy and onion-related domain indicators, including .onion and specific Tor gateway and Tor2web/torlink patterns. Such lookups can indicate anonymization or proxy use during command-and-control, data access, or exfiltration workflows. It relies on Zeek DNS telemetry, specifically DNS query names observed in network logs.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.