Authors - Sayuni Dewapriya, Pehan Gunasekara, Shenal Peiris, Charith Herath, Kavinga Yapa Abeywardena, Ayesha Wijesooriya Abstract - DNS is often trusted within modern network environments, making it a common channel for covert communication, malware activity, and infrastructure abuse. This paper presents a near-real-time AI/ML-based DNS threat detection framework designed to identify suspicious DNS behaviour and transform raw network activity into actionable security events. The proposed approach combines machine learning, behavioural analysis, flow-based detection, event aggregation, risk scoring, and contextual threat intelligence to improve visibility across plaintext DNS and DNS-over-HTTPS traffic patterns. The framework supports practical security operations by reducing raw alert noise and producing structured outputs suitable for dashboard monitoring and SIEM-based investigation. Evaluation using public datasets, generated attack traffic, and live DNS traffic demonstrates that the framework can support effective DNS threat monitoring, alert prioritisation, and SOC-level analysis.