High Volume DNS Requests to Single Domain

This rule identifies potential DNS tunneling or beaconing activity by detecting an unusually high volume of DNS queries (exceeding 50 requests) made to a specific domain name within a given timeframe. Such patterns are often associated with C2 communication or data exfiltration via the DNS protocol.