APT28 C2 Domain Connections - wellnessmedcare/freefoodaid/longsauce
Detects network and DNS activity involving domains known to be used by the threat actor APT28 for command and control, specifically for hosting WebDAV payloads, malicious LNK files, and weaponized documents.
Microsoft Sentinel (KQL)

