TWINLOOT reverse SOCKS5 tunnel via Teams TURN relay (SNI + SOCKS5 handshake signature)
This rule detects potential command-and-control (C2) activity from the TWINLOOT malware, which utilizes Microsoft Teams TURN relay infrastructure to establish a reverse SOCKS5 tunnel. The detection identifies connections to 'worldaz-msit.relay.teams.microsoft.com' followed immediately by a SOCKS5 handshake pattern (05 01 00), indicating encapsulated tunneling within the relay communication.
Suricata

