Velvet Ant Low-Frequency C2 Beaconing from Masqueraded Linux Service

This rule detects low-frequency, external network connections originating from Linux processes that are either explicitly known to be associated with malicious tools (e.g., gs-netcat, gsocket, atlasd) or are masquerading as legitimate system utilities (e.g., uptime, smbd) in a manner consistent with the Velvet Ant Operation Highland activity. The detection aggregates connections by process metadata and flags low-frequency outbound traffic, which is indicative of C2 beaconing.