Suspicious Credential Handling and Data Exfiltration Activity
Detects processes containing sensitive credential-related keywords (cookies, creds, password, token) in their command lines followed by a network connection to known suspicious remote IP addresses within a 60-minute window, suggesting potential credential exfiltration.
Microsoft Sentinel (KQL)

