Sysmon Event ID 22: DNS query
- Event ID
- 22
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- Network
- Default logging
- Needs configuration
What event 22 means
Sysmon event 22 records a DNS lookup performed through the Windows DNS client, together with the process that asked. It is logged whether the query succeeds or fails and whether the answer came from cache.
The value is attribution: network DNS logs show that a host resolved a domain, event 22 shows which executable did it. QueryResults lists the returned addresses (and CNAME records), which you can then match against event 3 connections from the same process.
Volume is high on workstations; configurations usually exclude well-known Microsoft, CDN and business domains. The telemetry relies on Windows 8.1 or later.
When it is logged
Sysmon 10.0 or later with a <DnsQuery> rule in the configuration. Not available on Windows 7 and earlier.
Only lookups made through the Windows DNS client are seen; a program that sends raw DNS packets or uses DNS over HTTPS inside the application bypasses it.
Key fields
| Field | What it tells you | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| ProcessGuid | Process that made the query; pivot to its event 1. | ||||||||
| Image | Executable that made the query. | ||||||||
| QueryName | Name that was resolved. | ||||||||
| QueryStatus | Result code of the query.
| ||||||||
| QueryResults | Answers returned, separated by semicolons. CNAME entries are shown with their record type; IPv4 answers may appear in IPv4-mapped IPv6 form (::ffff:a.b.c.d). | ||||||||
| User | Account of the process (newer Sysmon versions). |
Common benign sources
- Browsers, Teams, Office and Windows services resolving cloud and CDN names.
- Endpoint and update agents querying their vendor domains.
What attackers do that produces it
- Script hosts or LOLBins resolving rare or newly registered domains, paste sites or tunneling services.
- Many NXDOMAIN (
9003) answers from one process — domain generation algorithm (DGA) behavior. - Long random-looking subdomains in bulk — DNS tunneling or exfiltration.
Investigation tips
- Pivot on ProcessGuid to event 1 and to event 3 connections toward the IPs in QueryResults.
- Count QueryName across the fleet; domains seen on a single host are candidates for review.
- Check domain age and reputation for anything resolved by a script host.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
22 SigmaHQ detection rules (release r2026-07-01) target this event.
- Critical · 1
- High · 5
- Medium · 12
- Low · 4
- CriticalSuspicious Cobalt Strike DNS Beaconing - SysmonRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighDNS HybridConnectionManager Service BusRule by Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), SigmaHQ, DRL 1.1
- HighDNS Query by Finger UtilityRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- HighDNS Query for Anonfiles.com Domain - SysmonRule by pH-T (Nextron Systems), SigmaHQ, DRL 1.1
- HighDNS Query Tor .Onion Address - SysmonRule by frack113, SigmaHQ, DRL 1.1
- HighSuspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN SpoofingRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- MediumAppX Package Installation Attempts Via AppInstaller.EXERule by frack113, SigmaHQ, DRL 1.1
- MediumCloudflared Tunnels Related DNS RequestsRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumDNS Query Request By Regsvr32.EXERule by Dmitriy Lifanov, oscd.community, SigmaHQ, DRL 1.1
- MediumDNS Query To AzureWebsites.NET By Non-Browser ProcessRule by Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumDNS Query To Common Malware Hosting and Shortener ServicesRule by Ahmed Nosir (@egycondor), SigmaHQ, DRL 1.1
- MediumDNS Query To Devtunnels DomainRule by citron_ninja, SigmaHQ, DRL 1.1
- MediumDNS Query To MEGA Hosting WebsiteRule by Aaron Greetham (@beardofbinary) - NCC Group, SigmaHQ, DRL 1.1
- MediumDNS Query To Remote Access Software Domain From Non-Browser AppRule by frack113, Connor Martin, SigmaHQ, DRL 1.1
- MediumDNS Query To Visual Studio Code Tunnels DomainRule by citron_ninja, SigmaHQ, DRL 1.1
- MediumNotepad++ Updater DNS Query to Uncommon DomainsRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
- MediumSuspicious DNS Query for IP Lookup Service APIsRule by Brandon George (blog post), Thomas Patzke, SigmaHQ, DRL 1.1
- MediumTeamViewer Domain Query By Non-TeamViewer ApplicationRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- LowDNS Query Request By QuickAssist.EXERule by Muhammad Faisal (@faisalusuf), SigmaHQ, DRL 1.1
- LowDNS Query Request To OneLaunch Update ServiceRule by Josh Nickels, SigmaHQ, DRL 1.1
- LowDNS Query To Ufile.ioRule by yatinwad, TheDFIRReport, SigmaHQ, DRL 1.1
- LowDNS Server Discovery Via LDAP QueryRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.