DNS Tunneling via Unusually Long Subdomain Label Query

Detects DNS queries with exceptionally long request strings (30 characters or more), which is a common indicator of DNS tunneling or command and control (C2) communication. Adversaries often encode data within the subdomain portion of a DNS query to bypass network security controls.