DNS Data Exfiltration via Long Encoded Subdomain Queries

This rule detects potentially malicious DNS traffic where queries contain exceptionally long, encoded, or randomized subdomains. Attackers often use these patterns to exfiltrate data from a target network, bypassing traditional security controls by encapsulating information within DNS requests (DNS tunneling). The detection looks for DNS queries exceeding 100 bytes in length with specific character patterns indicative of Base64 or similar encoding.