Anthropic_AI_Misuse_Report_IOCs - GTG-50020 - Attacker egress IP matches
This rule monitors various logs (device network events, Entra ID sign-ins, cloud application events, and email events) for any interaction with a predefined list of indicator IP addresses identified as being associated with malicious actor egress traffic.
Microsoft Sentinel (KQL)

