Rogue ScreenConnect: Common Social Engineering Tactics
This rule detects network connections from devices to a predefined list of known malicious domains. It identifies attempts by internal systems to communicate with command and control servers, phishing sites, or other infrastructure associated with threat actors.
Microsoft Sentinel (KQL)

