DuckDNS / Dynamic-DNS C2 Beaconing (PowerShell RAT Pattern)

This rule detects network connections from common administrative processes (such as PowerShell, CMD, WScript, or Rundll32) to known dynamic DNS providers. This pattern is frequently indicative of malware beacons, command and control (C2) communication, or other unauthorized remote access tools utilizing dynamic DNS services to maintain connectivity to adversary infrastructure.