T1190: Public-Facing App Exploit Followed by Web Server Child Process/Egress
This rule monitors for web server exploit attempts (indicated by patterns like JNDI lookups or SQL injection sequences in URI/cookie data) that correlate with a surge in server-side errors (400+ status codes) and subsequent anomalous process creation or outbound network connections from the web server process.
Microsoft Sentinel (KQL)

