Interlock Ransomware TCP Beacon on Port 45588 Post-CVE-2026-20131

Detects outbound TCP traffic originating from the internal network to external hosts on TCP port 45588, which is associated with Interlock ransomware beaconing behavior. This rule monitors for initial TCP SYN packets, characteristic of an outbound connection attempt potentially related to command-and-control activity following the exploitation of CVE-2026-20131.