DNS over HTTPS (DoH) Activity Detected via Command Line Utilities
Detects the use of command-line tools like curl, wget, PowerShell, or Python to perform DNS over HTTPS (DoH) queries, identified by specific command-line arguments and connections to known public DoH resolvers. This behavior can be indicative of attempts to bypass local DNS monitoring or security controls.
Microsoft Sentinel (KQL)

