Potential Data Staging for Exfiltration
This rule detects the creation of large files (1MB or greater) with names suggestive of exfiltration or staging (e.g., containing 'exfil', 'stage', 'batch', 'zip', 'archive') in common temporary or public user directories. This behavior can indicate an adversary preparing data for exfiltration.
Microsoft Sentinel (KQL)

