Suspicious CDN and Direct-to-IP Network Exfiltration Indicators
This rule monitors for three categories of potentially suspicious network behavior: connections to common CDN providers over non-standard ports, high-volume HTTPS connections directly to IP addresses (IP-direct) bypassing standard domain resolution, and high-volume traffic to CDN infrastructure that may indicate domain fronting or C2 communication. Such patterns are often used by adversaries to mask egress traffic or exfiltrate data.
Microsoft Sentinel (KQL)

