Payroll Pirate - Known Attacker C2 IP Connection
This rule detects network connections from internal hosts to a list of known malicious IP addresses associated with the Payroll Pirate campaign (attributed to Storm-2755 and Storm-2657). Identifying these connections indicates potential communication with adversary-controlled infrastructure.
SentinelOne

