DGA — High-Entropy Subdomain Pattern (Domain Generation Algorithm)
04 DNS DGA High Entropy
Query
ASimDnsActivityLogs
| where TimeGenerated > ago(1h)
| where DnsResponseCode == 0
| extend SLD = tostring(split(DnsQuery, ".")[-2])
| where strlen(SLD) between (10 .. 40)
| extend
SLDLen = strlen(SLD),
HasDigits = SLD matches regex @"\d",
ConsonantCount = countof(SLD, "b") + countof(SLD, "c") + countof(SLD, "d")
+ countof(SLD, "f") + countof(SLD, "g") + countof(SLD, "h")
+ countof(SLD, "j") + countof(SLD, "k") + countof(SLD, "l")
+ countof(SLD, "m") + countof(SLD, "n") + countof(SLD, "p")
+ countof(SLD, "q") + countof(SLD, "r") + countof(SLD, "s")
+ countof(SLD, "t") + countof(SLD, "v") + countof(SLD, "w")
+ countof(SLD, "x") + countof(SLD, "y") + countof(SLD, "z")
| extend ConsonantRatio = todouble(ConsonantCount) / todouble(SLDLen)
| where ConsonantRatio > 0.65
and HasDigits == true
| summarize
DgaLikeDomains = dcount(DnsQuery),
QueryCount = count(),
SampleDomains = make_set(DnsQuery, 15),
FirstSeen = min(TimeGenerated),
LastSeen = max(TimeGenerated)
by SrcIpAddr, SrcHostname
| where DgaLikeDomains > 25Explanation
This query is designed to detect suspicious network activity that may indicate the presence of malware using Domain Generation Algorithms (DGA). Here's a simple breakdown of what it does:
-
Purpose: The query identifies computers (clients) that are communicating with domains generated by malware using DGA. These domains often have random-looking names and are used by malware to connect to command and control (C2) servers.
-
Detection Method:
- It analyzes DNS queries to find domains with certain characteristics:
- A high percentage of consonants (more than 65%).
- The presence of digits within the domain name.
- Domain names that are between 10 and 40 characters long.
- These characteristics are typical of DGA-generated domains, which are designed to look random.
- It analyzes DNS queries to find domains with certain characteristics:
-
Data Source: The query uses DNS activity logs from Windows DNS servers.
-
Frequency: The query runs every hour and looks at DNS queries from the past hour.
-
Alerting:
- If a computer queries more than 25 domains that match the DGA pattern, an alert is generated.
- The alert includes details such as the number of suspicious domains queried, sample domain names, and the time range of the activity.
-
Severity: The alert is classified as high severity because it indicates potential malware activity.
-
Use Case: This query is useful for detecting malware like Emotet, QakBot, Dridex, TrickBot, and others that use DGA to evade detection.
-
Output: The alert provides information about the source computer, including its hostname and IP address, and a sample of the suspicious domains queried.
Overall, this query helps security teams identify and respond to potential malware infections by detecting unusual DNS query patterns indicative of DGA activity.
Details

David Alonso
Released: July 28, 2026
Tables
Keywords
Operators
Severity
HighTactics
MITRE Techniques
Frequency: 1h
Period: 1h