JFrog Artifactory Cluster Join Key Read Followed by Outbound Transfer
Detects instances where an Artifactory process or user accesses highly sensitive configuration files (system.yaml, join.key) or API endpoints containing configuration data, followed closely (within 15 minutes) by an outbound network connection to a non-standard or external destination. This pattern is indicative of a potential credential theft attempt targeting the Artifactory join key, which is used to authenticate Artifactory nodes in a cluster, followed by potential data exfiltration or C2 communication using these credentials.
Microsoft Sentinel (KQL)

