DNS-over-HTTPS Tunneling to Known DoH Resolvers High Frequency
Detects high-volume, established TLS connections to common public DNS-over-HTTPS (DoH) providers (Google, Cloudflare, OpenDNS). Persistent high-frequency connections to these resolvers can be indicative of DNS tunneling, where an adversary encapsulates command-and-control or data exfiltration traffic within encrypted DNS queries to bypass network monitoring.
Suricata

