Exfiltration Over Webhook Endpoints T1567.004
Detects network connections from suspicious or unexpected processes to common public webhook and automation services, which may indicate data exfiltration or automated C2 communication.
Microsoft Sentinel (KQL)

