XWorm RAT Network Connection
This rule detects network connections to remote URLs containing indicators associated with the XWorm Remote Access Trojan (RAT). It specifically looks for 'xworm', 'x-worm', 'wormx', or '/xworm' within the RemoteUrl field of DeviceNetworkEvents.
Microsoft Sentinel (KQL)

