AiTM AWS Phishing Domain DNS/Network Connections - June 2026

This rule monitors DNS queries and network connections for access to a set of known domain names associated with Adversary-in-the-Middle (AiTM) phishing infrastructure. It correlates data from DNS events, device network logs, and virtual machine network connections to identify potential interactions with malicious phishing sites typically used to capture user credentials or session tokens.