Content Injection Detection via Unexpected IP and Proxy Content-Length Deviation

This rule monitors for two types of anomalous network behavior: first, it identifies connections to known domains from IP addresses not previously associated with those domains over a seven-day lookback period. Second, it identifies HTTP proxy responses (from Zscaler or Squid) where the content-length significantly deviates from the historical baseline for specific URLs. These patterns are potential indicators of C2 channel shifts or data exfiltration via web protocols.