DNS Tunneling Indicators: Long Labels or TXT/NULL Queries
Detects anomalous DNS traffic patterns indicative of command-and-control (C2) or data exfiltration over the DNS protocol. The rule identifies suspicious queries containing long, high-entropy subdomain labels that suggest payload encoding, as well as the use of TXT records for unauthorized data transmission.
Sigma

