Kali PhaaS Seen Again: DNS/Network Beaconing to Phishing Domains
This rule monitors DNS queries and network connection events for interactions with a list of domains associated with the Kali365 infrastructure. It flags activity by identifying both direct matches and subdomains associated with 'ssengineers.com' and 'clientengagenow.de', often used in phishing or C2 communications.
Microsoft Sentinel (KQL)

