DNS Tunneling: High-Volume TXT/NULL/CNAME Queries or Long Subdomain Labels

Detects anomalous DNS queries that utilize long labels or non-standard record types (TXT, NULL, CNAME) which are frequently associated with DNS tunneling and command-and-control communication. The rule flags endpoints with a high volume of these suspicious requests or exceptionally long domain labels.