DoH C2 Abuse - Non-Browser Connections to Known DoH Providers on 443
Detects network traffic on port 443 originating from non-browser processes destined for known DNS-over-HTTPS (DoH) providers (Cloudflare, Google, Quad9). This behavior can indicate an attempt to bypass standard network DNS filtering or to establish Command and Control (C2) communication channels using the DoH protocol.
Microsoft Sentinel (KQL)

