CVE-2026-27540 WordPress Network connections to known IOC Hunt
This rule identifies successful network connections from local devices to a predefined list of known malicious IP addresses within the last 7 days. Such connections often indicate active communication between a compromised endpoint and adversary-controlled infrastructure.
Microsoft Sentinel (KQL)

