FortiGate Edge Intrusions
This rule detects network connections to or from known suspicious IP addresses and requests to known suspicious domains. These indicators are often associated with command and control (C2) activity, malware distribution, or other malicious infrastructure.
Microsoft Sentinel (KQL)

