Malicious build.rs spawns network-capable child process during cargo build
Detects unexpected child processes spawned by Rust build tools (cargo/rustc) that initiate network connections during build processes. This rule specifically monitors for instances where the build process performs network-related activities associated with build scripts (build.rs) or cargo build commands, which may indicate malicious dependency injection or build-time exfiltration.
Microsoft Sentinel (KQL)

