Kimsuky WMI recon and exfil to /unicorn/mort.php C2
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
Microsoft Sentinel (KQL)

