Rare DNS over HTTPS Usage Combined with Windows Registry Run-Key Persistence
This rule detects potential malicious activity where a process attempts to communicate over DNS over HTTPS (DoH) using common public resolvers (e.g., Google DNS) while simultaneously establishing persistence via Windows Registry 'Run' keys. It excludes common, legitimate applications known to use DoH, focusing on unexpected processes. The detection relies on correlating network events (DoH to known public resolvers) with registry modification events occurring within a 30-minute window of the network activity.
Microsoft Sentinel (KQL)

