KREMLIN C2 Beaconing to Known IPs on Ports 4782/443
This rule detects outbound network connections from internal devices to a list of known malicious IP addresses associated with adversary command and control infrastructure. The rule specifically monitors connections over common ports, potentially indicating established communication with malicious servers.
Microsoft Sentinel (KQL)

