Potemkin DGA Loader - Process Generating High-Volume DNS Queries to Algorithmically Generated Domains

Detects anomalous, high-volume DNS query activity where a process attempts to resolve 20 or more unique domains within a 2-minute window. The query patterns match strings that are 8-20 characters long with common top-level domains, excluding known web browsers and standard network diagnostic utilities. This behavior is indicative of malware using Domain Generation Algorithms (DGA) for command and control or secondary communication channels.