High Volume Connections to Artifact/Maven Repositories
This rule detects a high volume of network connections (10 or more within an hour) from a single process to remote URLs containing 'artifact' or 'maven' on standard HTTP (port 80) or HTTPS (port 443) ports. This activity could indicate legitimate software development or build processes, but also potentially malicious activities such as supply chain compromise, data staging, or exfiltration of development-related artifacts.
Microsoft Sentinel (KQL)

