Malicious Domain Click Detection
This rule detects when a user clicks on a URL that contains a domain identified as malicious. The rule specifically looks for `UrlClickEvents` where the extracted domain from the URL matches any of the domains listed in the `malicious_domains` array. This can indicate a successful phishing attempt or an accidental click on a known malicious link.
Microsoft Sentinel (KQL)

