Endpoint network connections to Kimsuky home.kg infrastructure (domains & IPs)
Detects outbound network connections from endpoints to domains and IP addresses associated with the Kimsuky (APT43) threat actor group. This rule leverages endpoint network telemetry to identify potential command and control (C2) communication or data exfiltration activities.
Microsoft Sentinel (KQL)

