Zeek DNS queries matching Tor proxy and hidden service domains
Alerts on Zeek DNS queries for Tor proxy and onion domain indicators tied to possible anonymized activity.
- Product
- zeek
- Service
- dns
- Author
- Saw Winn Naung , Azure-Sentinel (SigmaHQ), DRL 1.1
- Published
- 2021-08-15
- Updated
- 2026-07-31
ATT&CK techniques
ExfiltrationRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags DNS lookup activity where the queried names match a set of common Tor proxy, hidden service, and related domain suffixes. Such lookups are often used to reach anonymity-network infrastructure, which can support malicious activity by hiding origin and intent. It relies on Zeek DNS telemetry, specifically the DNS query name suffixes observed in DNS logs.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Zeek DNS queries matching Tor proxy and hidden service domains
id: 27c6663f-7f96-49b4-8596-e391d65284f6
related:
- id: b55ca2a3-7cff-4dda-8bdd-c7bfa63bf544
type: similar
- id: 8384bd26-bde6-4da9-8e5d-4174a7a47ca2
type: similar
- id: a8322756-015c-42e7-afb1-436e85ed3ff5
type: derived
status: test
description: This rule flags DNS lookup activity where the queried names match a set of common Tor proxy, hidden service, and related domain suffixes. Such lookups are often used to reach anonymity-network infrastructure, which can support malicious activity by hiding origin and intent. It relies on Zeek DNS telemetry, specifically the DNS query name suffixes observed in DNS logs.
references:
- https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/ASimDNS/imDNS_TorProxies.yaml
- https://github.com/SigmaHQ/sigma/blob/master/rules/network/zeek/zeek_dns_torproxy.yml
author: Saw Winn Naung , Azure-Sentinel, Huntrule Team
date: 2021-08-15
modified: 2025-09-12
tags:
- attack.exfiltration
- attack.t1048
logsource:
service: dns
product: zeek
detection:
selection:
query|endswith:
- .hiddenservice.net
- .onion.ca
- .onion.cab
- .onion.casa
- .onion.city
- .onion.direct
- .onion.dog
- .onion.glass
- .onion.gq
- .onion.guide
- .onion.in.net
- .onion.ink
- .onion.it
- .onion.link
- .onion.lt
- .onion.lu
- .onion.ly
- .onion.mn
- .onion.network
- .onion.nu
- .onion.pet
- .onion.plus
- .onion.pt
- .onion.pw
- .onion.rip
- .onion.sh
- .onion.si
- .onion.to
- .onion.top
- .onion.ws
- .onion
- .s1.tor-gateways.de
- .s2.tor-gateways.de
- .s3.tor-gateways.de
- .s4.tor-gateways.de
- .s5.tor-gateways.de
- .t2w.pw
- .tor2web.ae.org
- .tor2web.blutmagie.de
- .tor2web.com
- .tor2web.fi
- .tor2web.io
- .tor2web.org
- .tor2web.xyz
- .torlink.co
condition: selection
falsepositives:
- Unknown
level: medium
license: DRL-1.1