DNS Tunneling via Long Subdomain Labels in Outbound DNS Queries

Detects abnormally long DNS queries characterized by repetitive alphanumeric patterns, which may indicate potential DNS tunneling activity used for C2 communication or data exfiltration. The rule flags DNS requests exceeding 60 characters with repeating label structures.