DNS Tunneling Long Subdomain Label Exfiltration Detection
This rule detects DNS queries containing an exceptionally long subdomain label (50 or more characters). Such patterns are often indicative of DNS tunneling techniques where data is encoded within the subdomain portion of a DNS query to bypass network security controls or establish command-and-control channels.
Suricata

