Transparent Tribe APT-C-56 known IOC hunt (hashes, C2 IP/domains)
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
Microsoft Sentinel (KQL)

