Signature: **ThreatClaw - domaine imitant microsoft (TLS SNI)** Class: social-engineering. Re-read the matched content and the triggering packet; confirm the traffic genuinely matches the signature and not a legitimate use. Flow direction: `established,to_server` (indicates the session initiator).
⚠️ No automatic action. Blocking the flow at the firewall / network-quarantining the host, to be decided by a human once the threat is confirmed.