Suspicious Outbound Connections with Consistent Timing (Beaconing)
This rule detects suspicious outbound network connections from devices that exhibit a consistent timing pattern (low standard deviation relative to the average time delta between connections) to public IP addresses. It specifically looks for connections that are not initiated by common browsers unless they are running in headless mode, or connections initiated by processes with low global prevalence or identified as Living Off The Land Binaries (LOLBAS). This pattern can indicate automated activity, command and control communication, or data exfiltration.
Microsoft Sentinel (KQL)

