Kali PhaaS Seen Again: DNS/Network Beaconing to Phishing Domains

This rule monitors DNS queries and network connection events for interactions with a list of domains associated with the Kali365 infrastructure. It flags activity by identifying both direct matches and subdomains associated with 'ssengineers.com' and 'clientengagenow.de', often used in phishing or C2 communications.