Bulk Data Exfiltration to AWS S3 via s5cmd Utility
Detects execution of the s5cmd command-line tool performing synchronization, copy, or move operations to a cloud storage URI (s3://) followed by an outbound network connection on port 443 within a 10-minute window. This behavior is indicative of potential data exfiltration to cloud storage.
CQL

