AI Agent Host DNS Tunneling Indicative of Covert C2

Detects anomalous DNS query patterns originating from AI agent hosts that are characteristic of DNS tunneling, such as the use of TXT or NULL records and excessively long subdomain labels. These techniques are often used by attackers to establish covert Command and Control (C2) channels and exfiltrate data by bypassing traditional HTTP/HTTPS egress filtering.