DNS Tunneling iodine/dnscat2 - Long Base32/Base64 Encoded Subdomain Label

This rule monitors DNS query traffic for unusually long, encoded subdomain labels (50 characters or more). Such patterns are indicative of data exfiltration or command-and-control (C2) communication using DNS tunneling tools like iodine or dnscat2, which encapsulate non-DNS protocols within the DNS query structure to evade network inspection.