Once in a BlueMoon: Malicious Domain and Hostname Hunt (BlueMoon Exploit Chain)

This rule detects DNS queries and network connections to a curated list of domains identified as malicious. It correlates events from DNS logs and device network logs to identify potential command-and-control (C2) or malicious infrastructure interaction.