DNS tunnelling
Data moved through DNS queries and answers. Detection is odd volume, long labels, and unusual types.
DNS is allowed almost everywhere, so some malware encodes data in query names and pulls data back in answers, often TXT or uncommon types. To a firewall that only allows DNS, it looks like names.
Signals, not a construction guide: high query volume from one host, unusually long labels, high-entropy names, lots of TXT or NULL, and clients talking to a resolver that is not yours. Baseline first. Software updates and some CDNs are already chatty.
See also: DNS, TXT record, Exfiltration, Network detection and response.
