DNS Tunneling - Anomalous Query Volume and Length to Single Domain
Detects potential DNS tunneling or Command and Control (C2) activity by analyzing DNS query patterns. The rule identifies anomalous behavior based on high query volume, excessive unique subdomain fanout to a single parent domain, and unusually long average query lengths. This combination is often indicative of data exfiltration or communication with a C2 server over the DNS protocol.
Cortex XDR

