T1090.002: Tengu Bot HTTP CONNECT Proxy Tunnel Handshake Responses

Detects anomalous HTTP CONNECT proxy handshake requests and responses associated with Tengu malware. The rule monitors for 'HTTP/1.1 200 Connection Established' and 'HTTP/1.1 407 Proxy Auth Required' responses initiated from internal hosts, as well as outgoing HTTP CONNECT requests containing a 'Proxy-Authorization' header that match established Tengu bot proxy patterns.