SOP-34: Outbound Threat-Intelligence Matched Connection
Detection and response procedures for outbound connections matching active threat intelligence indicators. Covers ThreatIntelligenceIndicator joins with DeviceNetworkEvents and DnsEvents, C2 beacon interval analysis using connection regularity and byte volume patterns.
Rudra Verma, Senior Security Architect & Researcher