DNS Tunneling Exfiltration via High-Volume High-Entropy Queries
This rule detects potential DNS tunneling activities used for data exfiltration. It identifies suspicious patterns by monitoring for a sustained, high volume (over 200) of DNS queries containing long, high-entropy encoded strings within the subdomain segment from a single client IP address. Legitimate traffic such as reverse DNS lookups is excluded to minimize noise.
Sigma

