Potential Automated Exfiltration
Detects potential data exfiltration attempts using PowerShell by identifying Invoke-WebRequest usage with specific flags (Put, ContentType, InFile) or encoding patterns (EncodedCommand) while targeting sensitive file extensions, directories, or suspicious network destinations.
Microsoft Sentinel (KQL)

