Blinder Tunnel IOC sweep: IPs, domains, and file hashes
This rule monitors endpoint telemetry (DNS queries, network connections, file creation, and process execution) to identify matches against a predefined list of known malicious indicators, including IP addresses, domains, and file hashes (SHA256). The rule differentiates between confirmed malicious activity and low-confidence indicators, providing a prioritized view of potential threats.
Microsoft Sentinel (KQL)

