Skip to content
DNS Client

DNS client Event ID 3006: DNS query started

DNS query is calledDNS Client event 3006 records the start of a DNS query on the host: queried name, record type and DNS servers. Channel is off by default; pair it with 3008.
3006
Event ID
3006
Channel
Microsoft-Windows-DNS-Client/Operational
Provider
Microsoft-Windows-DNS-Client
Log file
Microsoft-Windows-DNS-Client%4Operational.evtx
Category
Network
Default logging
Needs configuration

What event 3006 means

Event 3006 is written by the Windows DNS client when a name resolution is requested. It records the name (QueryName), the record type (QueryType), query options, the DNS server list and interface information. The result is logged separately by 3008 when the query completes.

The DNS Client operational channel gives host-level DNS visibility without Sysmon: every domain a machine tried to resolve, including names that never resolved. That is valuable for command-and-control, phishing and data exfiltration investigations, and for scoping which hosts contacted a malicious domain.

The EventData has no process field. The ProcessID in the event's System section is the only pointer to the requester; treat it as a lead and confirm with process or network telemetry. The channel is very verbose, so 3006 is often dropped in favor of 3008, which carries the name, the status and the answers.

When it is logged

Audit policy / configuration

Enable the Microsoft-Windows-DNS-Client/Operational channel (Event Viewer, or wevtutil sl Microsoft-Windows-DNS-Client/Operational /e:true). It is disabled by default.

Very high volume on busy hosts; increase the channel size or forward events to a collector. Sysmon event 22 (DNSEvent) is an alternative that records the querying process image.

Key fields

FieldWhat it tells you
QueryNameName being resolved, e.g. login.microsoftonline.com.
QueryTypeDNS record type requested (numeric).
ValueMeaning
1A (IPv4 address).
5CNAME.
12PTR (reverse lookup).
15MX.
16TXT — sometimes used for DNS tunneling or payload staging.
28AAAA (IPv6 address).
33SRV (e.g. domain controller location).
QueryOptionsQuery option flags passed by the caller (hexadecimal).
ServerListDNS servers the client will use for the query.
IsNetworkQueryWhether the query is sent to the network (as opposed to answered locally).
NetworkQueryIndexIndex of the network query attempt.
InterfaceIndexIndex of the network interface used.
IsAsyncQueryWhether the query is asynchronous.

Common benign sources

  • Browsers, Office, update and telemetry services resolving cloud endpoints continuously.
  • SRV lookups for domain controllers and LDAP/Kerberos services on domain members.
  • Reverse (PTR) lookups by management and security tools.

What attackers do that produces it

  • Resolution of known malicious or newly registered domains by an implant or phishing payload.
  • High volumes of long, random-looking subdomains of one domain (DNS tunneling or exfiltration), often with TXT queries.
  • Algorithmically generated domain names (DGA) queried in bursts, most failing to resolve.

Investigation tips

  • Pair each 3006 with the 3008 for the same QueryName to get the status and returned addresses.
  • Search all collected hosts for an indicator domain to scope which machines resolved it and when.
  • Count distinct subdomains per parent domain to reveal tunneling; long labels and TXT types are strong hints.
  • Use the System ProcessID as a lead and confirm the requesting program with 4688, Sysmon 1 or Sysmon 22.

MITRE ATT&CK techniques

TechniqueTactics
T1071.004 Application Layer Protocol: DNSCommand and Control
T1568.002 Dynamic Resolution: Domain Generation AlgorithmsCommand and Control
T1572 Protocol TunnelingCommand and Control

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading