High-Entropy DNS Subdomain Beaconing (Possible AI-Generated Tunneling)
Detects DNS queries containing long, high-entropy subdomain labels, which are characteristic of DNS tunneling techniques. Adversaries use DNS tunneling to bypass network controls by embedding C2 communications within DNS protocol fields. This rule identifies suspicious query structures, specifically targeting extended length and high character diversity in subdomains while filtering out common CDN domains that exhibit similar structural behaviors.
Sigma

