Uncommon Process Beaconing to Public IP via TLS
This rule identifies potential command-and-control (C2) beaconing behavior by detecting repetitive, consistent connections (low jitter) to public IP addresses over common TLS ports (443, 8443, 4443, 9443) from processes that do not have a known history of connecting to those destinations. It establishes a baseline of historical connections to filter out legitimate traffic and uses a statistical analysis of connection intervals to highlight suspicious, non-human-like automated communication patterns.
Microsoft Sentinel (KQL)

