Potential Rogue Device Detection
This rule monitors firewall traffic logs to identify connections directed at managed internal endpoints originating from devices not tracked by the endpoint management system. It flags potential rogue or unauthorized devices performing multi-target reconnaissance or communication across the internal network.
CQL

