nslookup uses an internal DNS engine so it doesn't get seen by Win32 DNS API. PacketBeat can be used to dissect raw DNS traffic on the client adapter. That's the only way, outside blocking port 53 outbound from usermode apps. Which might be interesting...
Anybody in my network can tell me why nslookup does not log Windows Events 30xx, neither Sysmon 22, while most other tools doing DNS request are logged? What is the workaround for DNS tunneling detection based on client logs only (i insist)?