Ghostwriter/UNC1151 Phishing Domain Access via Keyword+TLD Pattern
This rule monitors DeviceNetworkEvents for connections to domains that match naming patterns and TLDs frequently associated with the Ghostwriter/UNC1151 threat group. The rule specifically looks for URLs containing common credential-harvesting keywords (e.g., login, verify, account) combined with specific TLDs (e.g., .digital, .icu, .cc.cd). Connections to known common public DNS providers are excluded.
Microsoft Sentinel (KQL)

