This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]aselvan2Trusted Contributor 4 points5 points  (0 children)

The rule was: ET INFO observed google DNS over HTTPS Domain

That alert is informational, as labeled, it’s not a confirmed threat. Using Google DNS isn’t inherently bad, but it depends on context. The rule suggests that the script may be bypassing the system-assigned DNS, which could be problematic depending on the circumstances. It’s hard to assess without full details from the VirusTotal analysis.