Anti-Forensics
Account Misuse
Audit Trail Saturation
Clear Browser Artifacts
Clear Email Artifacts
Code Contribution Obfuscation and Misrepresentation
Cross-System Activity Fragmentation
Decrease Privileges
Delayed Execution Triggers
Delete User Account
Deletion of Volume Shadow Copy
Disable Logging
Disk Wiping
File Deletion
File Encryption
Hide Artifacts
Hiding or Destroying Command History
Incremental Data Collection
Log Deletion
Log Modification
Message Deletion
Message Modification
Modify Windows Registry
Network Obfuscation
Parent Process ID Spoofing
Physical Destruction of Storage Media
Physical Removal of Disk Storage
Retention Window Exploitation
Rootkit
Stalling
Steganography
System Shutdown
System Time Modification
Timestomping
Tripwires
Trusted Tool Misuse
Uninstalling Software
Virtualization
- ID: AF029.005
- Created: 02nd August 2026
- Updated: 02nd August 2026
- Contributor: The ITM Team
Unauthorized Encrypted DNS Usage
A subject configures or uses an unauthorized encrypted Domain Name System (DNS) service to prevent organizational infrastructure from observing, recording, filtering, or enforcing domain-resolution activity.
Encrypted DNS protocols, including DNS over HTTPS (DoH) and DNS over Transport Layer Security (DoT), protect DNS queries from observation while they travel between the endpoint and the resolver. Although these protocols have legitimate privacy and security applications, their unauthorized use can bypass enterprise DNS servers, DNS filtering, threat-intelligence controls, and domain-level investigative logging.
The subject may enable encrypted DNS through browser settings, operating-system configuration, mobile applications, command-line utilities, or third-party resolver software. They may also select a public or personally controlled resolver that is not governed by the organization.
This behavior reduces investigators’ ability to determine which domains the subject attempted to access. Network telemetry may show only an encrypted connection to the resolver rather than the individual domain queries conducted through it. Unauthorized encrypted DNS may be used to conceal access to prohibited services, external infrastructure, anonymization platforms, remote-access services, or data-transfer destinations.
The use of encrypted DNS alone does not establish improper intent. Investigators should determine whether the resolver was approved, whether organizational DNS controls were deliberately bypassed, and whether the activity coincided with another infringement or anti-forensics behavior.