CurlRAT C2 Beaconing via curl to Known Ted Toolkit Domains
This rule detects potential command and control (C2) activity associated with the CurlRAT malware. It monitors for both the execution of 'curl' or 'curl.exe' processes with command lines containing known C2 domains, and network traffic originating from internal devices directed toward those same domains.
Microsoft Sentinel (KQL)

