TASK#STOMP C2 communication to known domains/paths/token
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
Microsoft Sentinel (KQL)

