High Volume Network Connections to Download/Release URLs

This rule detects processes making a high volume of network connections (10 or more within an hour) to URLs containing 'release' or 'download'. This behavior can be indicative of malware downloading additional components, updates, or exfiltrating data, but could also be legitimate software updates or large file transfers.