DNS Tunneling - Long High-Entropy Subdomain Query Bursts

Detects DNS tunneling attempts by identifying DNS queries with abnormally long subdomains (greater than 50 characters) that exhibit a high request rate (20 or more queries within 60 seconds). This behavior is characteristic of C2 communication tools such as iodine or dnscat2, which encode data within DNS query labels to bypass traditional network security controls.