Impossible Travel: Token Access from ARToken-Linked IPs

This rule monitors network and event logs to detect instances where a single user account, logged into a specific host, initiates connections to two or more distinct, potentially suspicious remote IP addresses. This pattern of multi-destination connection activity may indicate command and control communication, scanning behavior, or data staging.