Detect Potential Evasion Techniques Against Security ML Models
This rule detects suspicious network connections where the initiating process command line contains keywords indicative of evasion techniques such as 'obfuscate', 'encode', or 'encrypt'. It specifically looks for these activities over common web ports (80, 443, 8080, 8443) and triggers an alert if 10 or more such attempts are observed from a device within an hour.
Microsoft Sentinel (KQL)

