DNS-over-HTTPS query to public resolver (possible C2 lookup evasion)

Detects network traffic attempting to connect to common public DNS-over-HTTPS (DoH) providers (Cloudflare, Google, Quad9) via TLS SNI or HTTP headers. This activity is often associated with malware or malicious agents attempting to bypass traditional DNS monitoring for command and control (C2) communication.