TeamPCP ICP Canister C2
This rule detects network connections or DNS queries to a specific Internet Computer Protocol (ICP) domain and canister ID (tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io or tdtqy-oyaaa-aaaae-af2dq-cai). This pattern is associated with command and control (C2) activity, where compromised systems communicate with an adversary-controlled server.
Microsoft Sentinel (KQL)

