High Volume Data Exfiltration via Common Protocols
This rule detects potential data exfiltration by identifying devices that make a high number of network connections (3 or more within an hour) to various remote IPs using common file transfer and email protocols (FTP, SFTP, SMB, SMTP) on their standard ports (21, 22, 445, 25, 587). This pattern can indicate an adversary attempting to exfiltrate collected data from a compromised system.
Microsoft Sentinel (KQL)

