QTFY Infrastructure Communication (Anchored Domains, Aggregated Ranges)
This rule detects network connections and DNS queries associated with the QTFY proxy infrastructure, including specific domains, known proxy management system IPs, and suspicious IP ranges. This behavior is indicative of command and control (C2) activity utilizing proxy services to obfuscate traffic.
Microsoft Sentinel (KQL)

