Outbound Connection to Known Malicious Infrastructure
This rule detects outbound connections from internal devices to domains and IP addresses linked to the “SysScan” fake Microsoft security scanner campaign. These connections may indicate exposure to malicious infrastructure used for tricking victims into disabling legitimate antivirus solutions, as reported in recent threat intelligence.
Microsoft Sentinel (KQL)

