You can’t decrypt most TLS traffic. Which signals are still…

You can’t decrypt most TLS traffic. Which signals are still valid for detection? I. Flow metadata (timing/volume/ports)II. Full HTTP payload content inside TLS without decryptionIII. TLS fingerprints/cert characteristics (where visible)IV. DNS behavior/anomalies