Entra ID Guest Invitation from High-Risk or IP-Based Domain (T1136.003)

Detects instances where a guest user is invited to the organization using an email address from potentially malicious TLDs (e.g., .ru, .cn, .ir, .kp) or a domain structure that is represented as an IP address. These patterns are often associated with phishing, reconnaissance, or adversary attempts to gain a foothold in an environment by inviting external identities.