Forfiles Utility Used for Arbitrary Command Execution
Detects the use of 'forfiles.exe' with the '/c' execution parameter, a technique that can be abused to launch arbitrary commands while potentially bypassing application controls. This activity is often associated with defense evasion tactics.
Microsoft Sentinel (KQL)

