Most Popular Detection 2026: DNS Tunneling via High-Entropy TXT/NULL Query Bursts

Detects anomalous DNS traffic patterns where a single client host performs a high volume of TXT or NULL DNS queries containing long, high-entropy subdomain labels directed at a small set of domains. This behavior is indicative of DNS tunneling, frequently used for covert Command and Control (C2) communication or data exfiltration.