SOP-34: Outbound Threat-Intelligence Matched Connection

Detection and response procedures for outbound connections matching active threat intelligence indicators. Covers ThreatIntelligenceIndicator joins with DeviceNetworkEvents and DnsEvents, C2 beacon interval analysis using connection regularity and byte volume patterns.

2026-08-15T09:46:15.647Z
Rudra Verma, Senior Security Architect & Researcher