DNS C2 Beaconing via High-Frequency TXT Queries to Long Subdomains
This rule detects potential command and control (C2) beaconing activity using DNS tunneling. It monitors for a high frequency of DNS TXT record queries to long subdomains (exceeding 50 characters), which is a common characteristic of tools like DNScat and iodine that encode data within DNS requests.
Suricata

