Once in a BlueMoon: ShadowPad Fallback C2 IP Hunt (BlueMoon Exploit Chain)
This rule monitors DeviceNetworkEvents for any outbound network connections made to the specific IP address 79.133.56.90. This address is identified as malicious or a known indicator of compromise (IoC) and may indicate command and control (C2) communication or unauthorized data transfer originating from a managed endpoint.
Microsoft Sentinel (KQL)

