HUNT Outbound Connections to C2 IPs (2026-09-14 Feed)

This rule monitors DeviceNetworkEvents for outbound network connections to a list of known malicious IP addresses associated with various C2 frameworks and malware families, as identified by threat intelligence feeds (e.g., ThreatFox). Identifying these connections helps detect potential C2 communication and ingress tool transfer.