Backdoor.Mistic and Woodgnat/KongTuke C2 Network Connections
This rule detects network communication (connections, DNS queries, or proxy logs) between endpoints and a list of known malicious domains and IP addresses associated with Mistic and Woodgnat/KongTuke threat families. It identifies these activities across network event logs, DNS queries, and security logs.
Microsoft Sentinel (KQL)

