Most Important Detection 2026: DNS Tunneling for Covert Data Exfiltration
This rule detects potential DNS tunneling activity by analyzing DNS query logs for high entropy in subdomains, elevated volumes of TXT/NULL record types, and frequent NXDOMAIN responses. This pattern is characteristic of command-and-control (C2) or data exfiltration techniques using tools like dnscat2 or iodine, which encode data into DNS query labels.
Splunk (SPL)

