DNS/network connections to ted/curlRAT C2 domains
This rule detects network communication (via DNS queries, web logs, or device network events) with a list of known malicious domains associated with Command and Control (C2) activity.
Microsoft Sentinel (KQL)

