DNS Exfiltration via Long Base64-Encoded Subdomain Labels >50 Chars
This rule detects potential DNS exfiltration attempts by identifying DNS queries containing high-entropy subdomains of 51 characters or more, encoded in Base64. Adversaries may use long, encoded subdomains to tunnel data out of a network through the DNS protocol, bypassing traditional security controls.
Suricata

