Reverse DNS Query Activity

This rule detects DNS queries for reverse lookups, specifically those ending with '.in-addr.arpa' or '.ip6.arpa'. While legitimate, frequent or unusual reverse DNS queries from a specific device or process could indicate reconnaissance activities or attempts to map internal network infrastructure by an attacker.