← Back to hub

DNS Exfiltration Indicators

Detects DNS queries with abnormally long subdomains (80+ chars) — indicator of DNS tunneling used for C2 or data exfiltration.

🔒

Premium Content

This query requires an active subscription to access the code.

Get Access