Suspicious C2 Beaconing via Non-Browser Process on Port 80/443
Detects native Windows command and scripting interpreters (e.g., cmd.exe, powershell.exe, mshta.exe) initiating external network connections to multiple distinct IP addresses, which is often an indicator of automated C2 beaconing or lateral movement activity.
SentinelOne

