Inbound Traffic from Anthropic IP Range - SPL Rule
This rule correlates email sender activity with network, cloud, and identity logs by matching traffic against a specific IP range (160.79.104.0/21) identified as malicious or suspicious. The rule flags instances where this range appears as an email sender IP or as a remote/source IP address across various infrastructure indices, potentially indicating adversary communication or exfiltration.
Splunk (SPL)

