NW.js report.bin host-profiling module execution and beacon
This rule detects the execution of a file named 'report.bin' and correlates it with subsequent network connections originating from the same process. This behavior is indicative of a potential C2 heartbeat or exfiltration activity involving a non-standard or obfuscated executable.
Microsoft Sentinel (KQL)

