Data Exfiltration via Rclone or Cloud Sync Tools to Cloud Providers

Detects the execution of known command-line sync tools (Rclone, MEGAsync) or commands attempting to sync or move data to various cloud storage services (s3, gdrive, onedrive, mega, dropbox). The rule focuses on executions from suspicious or temporary directory paths and excludes processes signed by trusted publishers to minimize noise.