// REFERENCE

Sysmon 22 — DNS query

Log: Sysmon/Operational Medium risk

A process made a DNS query (Sysmon). It ties the process to the queried domain, ideal to detect DNS C2 and tunneling: random-looking domains, anomalous TXT lookups or resolutions from binaries that shouldn't query DNS.

Related tools

Work with this in:

Related

Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.