Anthropic_AI_Misuse_Report_IOCs - GTG-15001 - Deceptive dating app infrastructure

This rule detects interaction with specific infrastructure identified as deceptive dating applications. It monitors network communication, sign-in attempts, email interactions, and endpoint execution associated with known malicious domains (e.g., archat.us, heyhru.com, sitin.ai), specific IP addresses (38.129.138.244), and unique package identifiers (com.cavalier.nalo, com.qiga.vio). The detection logic spans across DeviceNetworkEvents, EntraIdSignInEvents, EmailUrlInfo, EmailEvents, DeviceEvents, and DeviceProcessEvents to identify exposure to these Indicators of Compromise (IOCs) across both network and endpoint layers.