Cobalt Strike DNS Beacon - Long Encoded Subdomain Query Bursts

Detects DNS queries with abnormally long subdomains matching patterns frequently used by Cobalt Strike DNS Beacons for command-and-control communications. The rule identifies hexadecimal or base32 encoded strings within subdomains that exceed 40 characters in length and occur frequently within a short time window.