DNS client Event ID 3008: DNS query completed
- Event ID
- 3008
- Channel
- Microsoft-Windows-DNS-Client/Operational
- Provider
- Microsoft-Windows-DNS-Client
- Log file
- Microsoft-Windows-DNS-Client%4Operational.evtx
- Category
- Network
- Default logging
- Needs configuration
What event 3008 means
Event 3008 is written by the Windows DNS client when a name resolution finishes. It carries the queried name (QueryName), record type (QueryType), the result code (QueryStatus) and the answers (QueryResults), which makes it the most useful event of the DNS Client channel.
QueryResults lists the returned records separated by semicolons: IP addresses (IPv4 often in ::ffff: mapped form) and CNAME targets. With it you can map a domain to the IPs a host actually contacted and pivot to network logs, firewall events (5156) or proxy data.
Failures matter too: a burst of 9003 (name does not exist) statuses for random-looking names is typical of DGA malware, and repeated lookups of one domain at a fixed interval can reveal beaconing.
When it is logged
Enable the Microsoft-Windows-DNS-Client/Operational channel (Event Viewer, or wevtutil sl Microsoft-Windows-DNS-Client/Operational /e:true). It is disabled by default.
Very high volume on busy hosts; increase the channel size or forward events to a collector. Sysmon event 22 offers similar data with the querying process image.
Key fields
| Field | What it tells you | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| QueryName | Name that was resolved. | ||||||||||
| QueryType | DNS record type (1 A, 28 AAAA, 5 CNAME, 12 PTR, 16 TXT, 33 SRV). | ||||||||||
| QueryOptions | Query option flags passed by the caller. | ||||||||||
| QueryStatus | Result code of the query (Win32 / DNS error code).
| ||||||||||
| QueryResults | Semicolon-separated answers: IP addresses and CNAME entries. Empty when the query failed. |
Common benign sources
- Continuous resolution of Microsoft, CDN and SaaS domains by the OS and applications.
- NXDOMAIN results from DNS suffix search lists (the client appends suffixes before trying the bare name).
- Resolution of internal names and domain controller SRV records.
What attackers do that produces it
- Resolution of C2 domains; the returned IPs identify the infrastructure to block and hunt for.
- DGA activity — many NXDOMAIN (
9003) results for random-looking names in a short time. - DNS tunneling — large numbers of unique subdomains under one parent domain, often TXT queries.
Investigation tips
- Search across hosts for an indicator domain or for any
QueryResultscontaining an indicator IP. - Pivot from the resolved IPs to connections (5156, Sysmon 3, firewall and proxy logs) to confirm contact.
- Build per-host timelines of first-seen domains around the time of an alert.
- Use the System
ProcessIDas a lead and confirm the requester with process telemetry (4688, Sysmon 1, Sysmon 22).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.