Windows Registry Changes Enabling DNS-over-HTTPS via Edge, Chrome, or Firefox Policies

Alerts on registry policy updates that enable DNS-over-HTTPS for Edge, Chrome, or Firefox on Windows.

FreeReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
Austin Songer (SigmaHQ), DRL 1.1
Published
2021-07-22
Updated
2026-07-30

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows registry policy settings that enable DNS-over-HTTPS in Microsoft Edge, Google Chrome, or Mozilla Firefox. Enabling DoH can reduce visibility into DNS query behavior and complicate detection of malicious activity such as data exfiltration or stealthy network usage. Telemetry is based on registry set events matching specific policy keys and values for each browser.

Related detections9 linkedT1112 — drag to rearrange
Suspicious GPG Decryption of Downloaded Payload via GPG
Suspicious Shell Command Obfuscation via printf Escape Encoding on VMware ESXi (via process_creation)
Malicious Enabling of Restricted Admin Mode via Registry by UAT-8837
Suspicious Enabling of Remote Desktop via fDenyTSConnections Registry by DeadLock Ransomware
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Suspicious Loopback Proxy Server Configured via Registry (via registry_set)
Malicious WDigest Credential Caching Enabled via Registry (via registry_set)
Hidden PowerShell Archive Extraction via ExtractToDirectory
Malicious Shell Payload Piped from curl to zsh
Windows Registry Changes Enabling DNS-over-HTTPS via Edge, Chrome, or Firefox Policies
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.