Security teams should be doing DPI, using a corporate controlled CA to decrypt the traffic and then feed it into a SIEM which should start screaming bloody murder when it detects a mismatch between SNI and the requested host
Lots of IoC base on DNS as well so that is out of the windows since the malicious traffic is inside TLS...:-/