ROOTBOY Actor Infrastructure Communication Detection
Detects network activity associated with the ROOTBOY actor, specifically identifying internal devices communicating with known malicious command and control (C2) IP addresses and subsequently attempting to access specific suspicious domains or URLs linked to the actor's infrastructure.
Microsoft Sentinel (KQL)

