Cloud Admin Command Abuse via Azure Run Command or AWS SSM SendCommand
Detects the execution of remote commands on cloud virtual machines (Azure RunCommand or AWS SSM SendCommand) during defined off-hours (18:00 to 06:00). This rule identifies potentially unauthorized administrative or management activity occurring outside of standard business hours across cloud environments.
Microsoft Sentinel (KQL)

