Callback Phishing - Suspicious RAT Outbound Connection After Browser Launch

This rule detects the execution of known remote access tools (such as AnyDesk, TeamViewer, or RustDesk) that are spawned as child processes from common web browsers. It correlates process creation events with subsequent network connections by these tools to public IP addresses over specific ports commonly used by remote access software, within a 30-minute timeframe of the process start.