IOC hunt: Sept2026 Anthropic report indicators (exfil, phishing, malware)
This rule performs a hunting activity across multiple telemetry sources (Network, Email, Endpoint) to detect known indicators of compromise (IOCs) associated with Anthropic threat intelligence reporting (September 2026). It looks for specific malware file names, command-line patterns, service installations, phishing email addresses, and C2 communication URLs.
Microsoft Sentinel (KQL)

