DNS Tunneling via High-Entropy/Long Subdomains or TXT/NULL Volume

Detects potential DNS tunneling activity by monitoring for unusually long DNS query strings (high entropy indicator), frequent usage of TXT or NULL DNS record types, and high query volume directed at a limited number of unique domains from a single host.