Rapid outbound activity following GapiUpdate/NeedleStealer wallet credential the
This rule detects potential automated cryptocurrency wallet draining activity by correlating the execution of known stealer processes (such as GapiUpdate or NeedleStealer) with subsequent outbound network connections to suspicious command-and-control domains or API endpoints within a 30-minute window.
Microsoft Sentinel (KQL)

