Suspicious File Download from Internet
Detects suspicious file downloads from the internet where common DLLs (wininet.dll, urlmon.dll, msxml3.dll) are initiating the file creation of executable, DLL, PowerShell, or batch files. The rule specifically looks for scenarios where 5 or more such files are created by the same initiating process on a device, indicating potential malicious activity like ingress tool transfer.
Microsoft Sentinel (KQL)

