OilRig (APT34 / Hazel Sandstorm) - PowerShell Backdoor DNS Tunneling C2

Detects command-line activity indicative of DNS tunneling, often used by OilRig (APT34) for C2 communication via BONDUPDATER. The rule monitors PowerShell or nslookup commands executing DNS TXT record queries paired with long, base64-encoded subdomains, a technique used for exfiltrating data or receiving commands.