Skip to content
Sysmon

Sysmon Event ID 22: DNS query

DNSEvent (DNS query)Sysmon event 22 logs a DNS query made by a process, with the name, status and answers. Links domains to processes for C2, tunneling and phishing hunts.
22
Event ID
22
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
Network
Default logging
Needs configuration

What event 22 means

Sysmon event 22 records a DNS lookup performed through the Windows DNS client, together with the process that asked. It is logged whether the query succeeds or fails and whether the answer came from cache.

The value is attribution: network DNS logs show that a host resolved a domain, event 22 shows which executable did it. QueryResults lists the returned addresses (and CNAME records), which you can then match against event 3 connections from the same process.

Volume is high on workstations; configurations usually exclude well-known Microsoft, CDN and business domains. The telemetry relies on Windows 8.1 or later.

When it is logged

Audit policy / configuration

Sysmon 10.0 or later with a <DnsQuery> rule in the configuration. Not available on Windows 7 and earlier.

Only lookups made through the Windows DNS client are seen; a program that sends raw DNS packets or uses DNS over HTTPS inside the application bypasses it.

Key fields

FieldWhat it tells you
ProcessGuidProcess that made the query; pivot to its event 1.
ImageExecutable that made the query.
QueryNameName that was resolved.
QueryStatusResult code of the query.
ValueMeaning
0Success.
9003DNS_ERROR_RCODE_NAME_ERROR — the name does not exist (NXDOMAIN).
9501DNS_INFO_NO_RECORDS — the name exists but has no record of the requested type.
QueryResultsAnswers returned, separated by semicolons. CNAME entries are shown with their record type; IPv4 answers may appear in IPv4-mapped IPv6 form (::ffff:a.b.c.d).
UserAccount of the process (newer Sysmon versions).

Common benign sources

  • Browsers, Teams, Office and Windows services resolving cloud and CDN names.
  • Endpoint and update agents querying their vendor domains.

What attackers do that produces it

  • Script hosts or LOLBins resolving rare or newly registered domains, paste sites or tunneling services.
  • Many NXDOMAIN (9003) answers from one process — domain generation algorithm (DGA) behavior.
  • Long random-looking subdomains in bulk — DNS tunneling or exfiltration.

Investigation tips

  • Pivot on ProcessGuid to event 1 and to event 3 connections toward the IPs in QueryResults.
  • Count QueryName across the fleet; domains seen on a single host are candidates for review.
  • Check domain age and reputation for anything resolved by a script host.

MITRE ATT&CK techniques

TechniqueTactics
T1071.004 Application Layer Protocol: DNSCommand and Control
T1568.002 Dynamic Resolution: Domain Generation AlgorithmsCommand and Control
T1572 Protocol TunnelingCommand and Control

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

22 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Critical · 1
  • High · 5
  • Medium · 12
  • Low · 4

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideSysmon Event ID 22: DNS queries, C2 domains and exfiltration

Sources and further reading