DNS client Event ID 3006: DNS query started
- Event ID
- 3006
- Channel
- Microsoft-Windows-DNS-Client/Operational
- Provider
- Microsoft-Windows-DNS-Client
- Log file
- Microsoft-Windows-DNS-Client%4Operational.evtx
- Category
- Network
- Default logging
- Needs configuration
What event 3006 means
Event 3006 is written by the Windows DNS client when a name resolution is requested. It records the name (QueryName), the record type (QueryType), query options, the DNS server list and interface information. The result is logged separately by 3008 when the query completes.
The DNS Client operational channel gives host-level DNS visibility without Sysmon: every domain a machine tried to resolve, including names that never resolved. That is valuable for command-and-control, phishing and data exfiltration investigations, and for scoping which hosts contacted a malicious domain.
The EventData has no process field. The ProcessID in the event's System section is the only pointer to the requester; treat it as a lead and confirm with process or network telemetry. The channel is very verbose, so 3006 is often dropped in favor of 3008, which carries the name, the status and the answers.
When it is logged
Enable the Microsoft-Windows-DNS-Client/Operational channel (Event Viewer, or wevtutil sl Microsoft-Windows-DNS-Client/Operational /e:true). It is disabled by default.
Very high volume on busy hosts; increase the channel size or forward events to a collector. Sysmon event 22 (DNSEvent) is an alternative that records the querying process image.
Key fields
| Field | What it tells you | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| QueryName | Name being resolved, e.g. login.microsoftonline.com. | ||||||||||||||||
| QueryType | DNS record type requested (numeric).
| ||||||||||||||||
| QueryOptions | Query option flags passed by the caller (hexadecimal). | ||||||||||||||||
| ServerList | DNS servers the client will use for the query. | ||||||||||||||||
| IsNetworkQuery | Whether the query is sent to the network (as opposed to answered locally). | ||||||||||||||||
| NetworkQueryIndex | Index of the network query attempt. | ||||||||||||||||
| InterfaceIndex | Index of the network interface used. | ||||||||||||||||
| IsAsyncQuery | Whether the query is asynchronous. |
Common benign sources
- Browsers, Office, update and telemetry services resolving cloud endpoints continuously.
- SRV lookups for domain controllers and LDAP/Kerberos services on domain members.
- Reverse (PTR) lookups by management and security tools.
What attackers do that produces it
- Resolution of known malicious or newly registered domains by an implant or phishing payload.
- High volumes of long, random-looking subdomains of one domain (DNS tunneling or exfiltration), often with TXT queries.
- Algorithmically generated domain names (DGA) queried in bursts, most failing to resolve.
Investigation tips
- Pair each 3006 with the 3008 for the same
QueryNameto get the status and returned addresses. - Search all collected hosts for an indicator domain to scope which machines resolved it and when.
- Count distinct subdomains per parent domain to reveal tunneling; long labels and TXT types are strong hints.
- Use the System
ProcessIDas a lead and confirm the requesting program with 4688, Sysmon 1 or Sysmon 22.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.