API Key Exposure in FTP Directory Listing
This rule detects potential exposure of API keys, tokens, or secrets within FTP directory listings. It specifically looks for network events on remote port 21 (FTP) where the 'RemoteUrl' contains keywords like 'api_key', 'apikey', 'token', 'secret', or 'key=' during a network signature inspection.
Microsoft Sentinel (KQL)

