APT 35 - Charming Kitten - G0059 — Magic Hound | Potential User clicks on DDNS or lure-themed domains
This rule detects user interaction with potentially malicious URLs from known Dynamic DNS (DDNS) providers or URLs containing suspicious keywords frequently associated with phishing lures (e.g., login, auth, verify, mfa). It filters out known legitimate Microsoft domains to reduce noise.
Microsoft Sentinel (KQL)

