HTTP Response Content Injection via Proxy Logs (T1659)
This rule monitors network logs (from proxies and firewalls) for web traffic (HTTP GET requests) containing suspicious JavaScript code injection patterns in the request context or message fields. It specifically looks for common XSS indicators such as <script tags, eval(), document.write(), fromCharCode(), and atob().
Microsoft Sentinel (KQL)

