Threat Actor VPN Connection Detection
This rule monitors for network connections, firewall traffic, and Entra ID authentication events involving known malicious IP addresses (the 'Wall of Shame'). The rule specifically flags interactions occurring over common VPN ports, suggesting potential unauthorized access or persistence attempts via VPN services.
Microsoft Sentinel (KQL)

