UNC1151 Ghostwriter Phishing Infrastructure Network Connections
This rule detects network connections from internal hosts to identified C2 or phishing infrastructure associated with the threat actor group UNC1151 (also known as Ghostwriter). It monitors both host-based network events (via DeviceNetworkEvents) and centralized network security logs (via CommonSecurityLog) for traffic targeting a curated list of known malicious IP addresses.
SentinelOne

