Outbound Connection to File Sharing or Temporary Email Services
This rule detects outbound network connections to URLs associated with common file sharing services (e.g., Dropbox, Mega, Gofile) or temporary email providers (e.g., Temp-Mail). Such connections can indicate data exfiltration attempts, use of unsanctioned services, or communication with command and control infrastructure.
Microsoft Sentinel (KQL)

