IronToll Government-Impersonation Phishing Domain Query

Detects DNS queries, TLS SNI, and HTTP Host header traffic associated with the IronToll phishing campaign. The rule specifically monitors for government-impersonating domains and lookalike domains utilizing various non-standard top-level domains (TLDs).