net_dns_tunnel
Detects DNS tunneling by analyzing subdomain length distribution, label entropy, and query frequency to uncover hidden data exfiltration.
Instructions
DNS tunneling detection. Analyzes subdomain length distribution, label entropy, TXT record usage, query frequency per domain, and unique subdomain counts to identify DNS-based covert channels.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| file_path | Yes | Path to PCAP capture file |