Outbound Connections to GTG-20006/GTG-50014 C2 IPs (Sept 2026)

This rule monitors DeviceNetworkEvents for outbound connections to a list of known malicious or suspicious IP addresses. This activity is indicative of potential command and control (C2) communication or unauthorized data exfiltration.