DNS C2 Tunneling - Long Subdomain Label Beaconing

This rule detects potential command and control (C2) activity leveraging DNS tunneling. It identifies high-frequency DNS queries that contain unusually long subdomain labels (51 characters or more), which is a common technique used to encode data or commands within DNS protocol traffic to bypass network security controls.