IOC Sweep for Outbound connections to confirmed Azazel C2/staging/exfil infrastructure
This rule detects successful network connections to known malicious IP addresses or the domain 'forgitlab.com', which are associated with the Azazel malware threat infrastructure.
Microsoft Sentinel (KQL)

