DNS Tunneling Exfiltration - Long Query with Base64/Hex Encoded Labels
Detects DNS query traffic where the subdomain label length exceeds 50 characters and contains patterns consistent with Base64 or Hexadecimal encoding. This behavior is indicative of potential data exfiltration or command-and-control communication performed over the DNS protocol by tunneling data within query labels.
Suricata

