UAT-8302 NetDraft MS Graph API C2 via Non-Microsoft-Signed Process

This rule monitors for outbound network connections to 'graph.microsoft.com' initiated by processes that are either unsigned or not digitally signed by Microsoft. It further correlates these connections with proxy logs to identify processes utilizing non-standard or unexpected User-Agents. This behavior is indicative of potentially malicious activity attempting to masquerade as legitimate Microsoft services or using the Microsoft Graph API for command and control or data exfiltration.