Most Popular Detection 2026: DNS Tunneling for Covert Command and Control
This rule detects potential DNS tunneling activities often associated with Command and Control (C2) communication. It monitors for anomalous patterns including excessively long DNS query labels, the use of uncommon DNS record types (TXT or NULL), and high volumes of DNS traffic directed towards specific domains. These behaviors are common indicators of data exfiltration or covert beaconing attempts designed to bypass traditional network security controls.
YARA-L

