Rule Info
Name
Unusually Long DNS Query - Network
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects unusually long DNS queries that may indicate DNS tunneling, data exfiltration attempts, or C2 communication.
Usage of DNS for C&C communication or data exfiltration often involves crafting long DNS queries to encode information.
Reference
Internal Research
Date
2026-04-02 00:00:00
Modified
None
Id
d5444830-c0e5-47aa-9fa7-c0e7ba5fcc39
Tags
attack.exfiltration attack.t1048 attack.command-and-control attack.t1071.004
Type
Nextron Sigma feed only (private)
