Exfiltration Over Suspicious Remote URL via Standard Ports

This rule detects potential data exfiltration attempts by monitoring for network connections to URLs containing suspicious substrings (bit, onion, .cc, .su) over common web and DNS ports (53, 80, 443, 8080). It flags high-frequency unique connection attempts from a single device, which may indicate command-and-control (C2) traffic or data exfiltration over covert channels.