Bad actors sometimes try exfil through port 53. Depending on your firewall data, it can be tough to spot this. Below in #splunk I look for unblocked traffic where median transfer volume is higher than 5 standard deviations from the norm.

#informationsecurity
#cybersecurity