Skip to content
DNS Client

DNS client Event ID 3008: DNS query completed

DNS query is completedDNS Client event 3008 records a completed DNS query: name, type, status code and resolved addresses. Host-level DNS history; channel is off by default.
3008
Event ID
3008
Channel
Microsoft-Windows-DNS-Client/Operational
Provider
Microsoft-Windows-DNS-Client
Log file
Microsoft-Windows-DNS-Client%4Operational.evtx
Category
Network
Default logging
Needs configuration

What event 3008 means

Event 3008 is written by the Windows DNS client when a name resolution finishes. It carries the queried name (QueryName), record type (QueryType), the result code (QueryStatus) and the answers (QueryResults), which makes it the most useful event of the DNS Client channel.

QueryResults lists the returned records separated by semicolons: IP addresses (IPv4 often in ::ffff: mapped form) and CNAME targets. With it you can map a domain to the IPs a host actually contacted and pivot to network logs, firewall events (5156) or proxy data.

Failures matter too: a burst of 9003 (name does not exist) statuses for random-looking names is typical of DGA malware, and repeated lookups of one domain at a fixed interval can reveal beaconing.

When it is logged

Audit policy / configuration

Enable the Microsoft-Windows-DNS-Client/Operational channel (Event Viewer, or wevtutil sl Microsoft-Windows-DNS-Client/Operational /e:true). It is disabled by default.

Very high volume on busy hosts; increase the channel size or forward events to a collector. Sysmon event 22 offers similar data with the querying process image.

Key fields

FieldWhat it tells you
QueryNameName that was resolved.
QueryTypeDNS record type (1 A, 28 AAAA, 5 CNAME, 12 PTR, 16 TXT, 33 SRV).
QueryOptionsQuery option flags passed by the caller.
QueryStatusResult code of the query (Win32 / DNS error code).
ValueMeaning
0Success.
1460ERROR_TIMEOUT — no response within the timeout.
9003DNS_ERROR_RCODE_NAME_ERROR — the name does not exist (NXDOMAIN).
9501DNS_INFO_NO_RECORDS — the name exists but has no record of the requested type.
QueryResultsSemicolon-separated answers: IP addresses and CNAME entries. Empty when the query failed.

Common benign sources

  • Continuous resolution of Microsoft, CDN and SaaS domains by the OS and applications.
  • NXDOMAIN results from DNS suffix search lists (the client appends suffixes before trying the bare name).
  • Resolution of internal names and domain controller SRV records.

What attackers do that produces it

  • Resolution of C2 domains; the returned IPs identify the infrastructure to block and hunt for.
  • DGA activity — many NXDOMAIN (9003) results for random-looking names in a short time.
  • DNS tunneling — large numbers of unique subdomains under one parent domain, often TXT queries.

Investigation tips

  • Search across hosts for an indicator domain or for any QueryResults containing an indicator IP.
  • Pivot from the resolved IPs to connections (5156, Sysmon 3, firewall and proxy logs) to confirm contact.
  • Build per-host timelines of first-seen domains around the time of an alert.
  • Use the System ProcessID as a lead and confirm the requester with process telemetry (4688, Sysmon 1, Sysmon 22).

MITRE ATT&CK techniques

TechniqueTactics
T1071.004 Application Layer Protocol: DNSCommand and Control
T1568.002 Dynamic Resolution: Domain Generation AlgorithmsCommand and Control
T1572 Protocol TunnelingCommand and Control

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading