// REFERENCE
Sysmon 22 — DNS query
Log: Sysmon/Operational
Medium risk
A process made a DNS query (Sysmon). It ties the process to the queried domain, ideal to detect DNS C2 and tunneling: random-looking domains, anomalous TXT lookups or resolutions from binaries that shouldn't query DNS.
Related tools
Work with this in:
Related
1
Sysmon 1 — Process creation 3
Sysmon 3 — Network connection 7
Sysmon 7 — Image (DLL) loaded 8
Sysmon 8 — CreateRemoteThread 10
Sysmon 10 — Process access 11
Sysmon 11 — File created
Sysmon 1 — Process creation 3
Sysmon 3 — Network connection 7
Sysmon 7 — Image (DLL) loaded 8
Sysmon 8 — CreateRemoteThread 10
Sysmon 10 — Process access 11
Sysmon 11 — File created
Original descriptions based on Microsoft's public documentation. IDs and fields may vary with the Windows version and the active audit policy.