DNS TXT Record Query Used for Remote Command Execution
Detects the use of PowerShell to perform DNS lookups for TXT records followed by immediate command execution, such as using 'Invoke-Expression' or 'Start-Process'. This pattern is frequently indicative of fileless command-and-control (C2) communication where stage-payload commands or scripts are retrieved via DNS TXT records to evade detection.
Microsoft Sentinel (KQL)

