Outbound connection to weaponized placeholder domain third-party.com

Detects network connection attempts to 'third-party.com', which was historically a common documentation placeholder domain but has since been acquired by attackers to serve malicious infrastructure. This rule flags processes interacting with this domain, identifying potential exploitation via copy-pasted code or documentation examples.