Suspicious DNS Query to Known Cloud C2 Infrastructure
This rule detects DNS requests to common cloud-based infrastructure providers often used by adversaries for Command and Control (C2) operations, including AWS API Gateway, Azure App Service, Google Cloud Functions, and Cloudflare Workers. These domains are frequently leveraged to host redirectors, beaconing infrastructure, or malicious payloads.
CQL

