Suspicious Outbound HTTP UserAgent

This detection monitors the CommonSecurityLog (which adheres to the Common Event Format - CEF) for indications of malicious network activity. Specifically, it flags outgoing HTTP requests originating from system utilities such as curl, wget, and PowerShell. These requests are often leveraged by attackers for data theft (exfiltration) or establishing command-and-control channels. Review the full user agent string and destination hostname. Investigate the source IP and user context. Check whether the tool usage aligns with expected behavior for the host or user. Correlate with other indicators such as unusual process execution, file access, or authentication anomalies. Escalate if the destination is unknown or suspicious. Remove the KQL summarise line to view more details. UA_Check and SafeHosts will require tuning for your specific environment setup and traffic.