Suspicious Command-Line Activity with System Binaries
Detects suspicious command-line executions involving common Windows system binaries (rundll32.exe, mshta.exe, certutil.exe, wmic.exe) combined with keywords often associated with network communication or data transfer (http, https, base64, /transfer). This pattern can indicate attempts at downloading malicious payloads, exfiltrating data, or executing encoded commands.
Microsoft Sentinel (KQL)

