Possible Botnet C2 Beaconing via Periodic Outbound Connections
This rule detects potential Command and Control (C2) beaconing activity by identifying periodic outbound network connections from suspicious or non-browser processes. It analyzes the time deltas between successful network connections; if the standard deviation of these intervals is low (indicating consistent timing) and a sufficient number of connections occur, it flags the behavior as a potential C2 heartbeat.
Microsoft Sentinel (KQL)

