Once in a BlueMoon: Malicious Download URL Hunt (BlueMoon Exploit Chain)
This rule detects network connections and HTTP requests to known malicious URLs, including file downloads associated with C2 infrastructure and malware distribution campaigns. It monitors both direct device network events and HTTP requests logged through security product events to identify potential secondary-stage payload delivery.
Microsoft Sentinel (KQL)

