Possible Go RAT persistent C2 on TCP/5556 (network log)
This rule detects potential command-and-control beaconing activity associated with the Go RAT used in the GapiUpdate campaign. It monitors for outbound network connections over TCP port 5556 to a known malicious C2 IP address, or alternatively, detects persistent outbound activity to other external (non-RFC1918) IP addresses characterized by multiple successive connections within a 10-minute window, which mimics the behavior of persistent beaconing.
Microsoft Sentinel (KQL)

