Remcos RAT Loader WebSocket Communication to Known C2
This rule detects WebSocket communication attempts from a device to known command and control (C2) IP addresses associated with the Remcos Remote Access Trojan (RAT). It specifically looks for network events where the remote URL contains 'ws://', 'wss://', or 'websocket' and the remote IP address matches one of the listed indicators of compromise (IOCs).
Microsoft Sentinel (KQL)

