DNS Tunneling Indicators: Long Queries or TXT/NULL Record Abuse

Detects potential DNS tunneling or command-and-control (C2) traffic by identifying abnormally long DNS query names, which often indicate encoded data channels, and suspicious usage of TXT or NULL DNS records, which are frequently used by tools like Cobalt Strike, dnscat2, and iodine for C2 communication.