DNS C2 Beaconing via Long Random Subdomains
This rule detects potential command and control (C2) beaconing activity using DNS by identifying high-frequency, long, and random subdomain queries. It monitors for DNS requests that exceed 40 bytes in size, feature complex alphanumeric subdomains, and exceed a defined threshold of 10 requests within a 60-second window, which is indicative of DNS tunneling or command-and-control exfiltration.
Suricata

