Anthropic_AI_Misuse_Report_IOCs - GTG-50029 - European political targeting IOC matches

This rule detects activity associated with known indicators of compromise (IOCs) related to European political targeting campaigns. It monitors network, email, and authentication logs for connections to specific malicious domains (including .onion addresses) and IP addresses. The rule spans multiple data sources, including device network events, Entra ID sign-in logs, cloud application events, and email communications.