Rogue ScreenConnect: Common Social Engineering Tactics

This rule detects network connections from devices to a predefined list of known malicious domains. It identifies attempts by internal systems to communicate with command and control servers, phishing sites, or other infrastructure associated with threat actors.