PIVOTPIPE C2 Traffic to Known Cobalt Strike Server 45.32.253.166:8088

Detects network communication to a known malicious IP address (45.32.253.166) associated with the PIVOTPIPE RAT using Cobalt Strike C2 beaconing patterns. The rule identifies TCP connections, HTTP GET requests for beacon check-ins, and HTTP POST requests for task responses.