DNS TXT Record Exfiltration - Large TXT RDATA Response
Detects DNS TXT query responses containing anomalously large RDATA payloads (exceeding 100 bytes). Large TXT records are frequently used in DNS tunneling or data exfiltration scenarios to smuggle data out of a network while bypassing traditional network security controls. The rule applies a threshold limit to identify persistent, potentially malicious exfiltration activity from a specific source over a 60-second window.
Suricata

