Most Important Detection 2026: DNS Tunneling Command and Control
This rule detects potential DNS tunneling activities often used for Command and Control (C2) communication. It monitors for high volumes of DNS requests involving records commonly abused for tunneling (TXT, NULL, CNAME) from a single host to a specific parent domain. It further identifies suspicious patterns characterized by long, high-entropy subdomain labels (>45 characters) and a high frequency of distinct labels, which are indicative of encoded C2 traffic.
CQL

