nslookup.exe TXT Record Query - DNS C2 Tunneling (T1071.004)
Detects the use of nslookup.exe to query DNS TXT records from non-Microsoft signed processes. This behavior is often associated with DNS-based Command and Control (C2) channels or data exfiltration techniques where small amounts of data are encoded within DNS TXT records.
SentinelOne

