Sauron Loader TLS SNI to hardcoded C2 registration domains

This rule detects network activity associated with the Sauron Loader malware. It monitors for TLS connections to known hardcoded C2 domains and identifies HTTP requests following a specific pattern of randomized command and control (C2) paths combined with suspicious User-Agent headers (Windows NT with Edge/Edg).