Hunt For ClearFake/Amatera/ZigCryptoStealer C2 & Infrastructure
Detects network connections to known command and control (C2) infrastructure, including hardcoded malicious domains, specific C2 IP addresses, and suspicious GitHub access patterns by processes other than standard web browsers, which may indicate malicious ingress tool transfer or C2 communication.
Microsoft Sentinel (KQL)

