Suspicious DNS Query Characteristics
This rule detects DNS queries with suspicious characteristics that may indicate DNS tunneling, data exfiltration, or command and control activity. It identifies queries with unusually long names, long first labels combined with high entropy, or a high number of subdomains combined with a long first label. Exclusions are made for common legitimate DNS suffixes and specific service-related domains.
Microsoft Sentinel (KQL)

