Inbound Traffic from Anthropic IP Range - S1QL Rule
This rule detects various event types (email, identity authentication, network connections, and cloud audit logs) originating from or interacting with the specific IP address range 160.79.104.0/22 to 160.79.111.0/22, which is associated with known malicious activity.
SentinelOne

