DNS Tunneling via Long Subdomain

Detect DNS tunnelling via long subdomain labels. The query is useful for identifying DNS queries with unusually long request strings (typically 40+ characters per label) and high volumes of repetitive requests used by attackers to exfiltrate data or run command-and-control (C2) channels.