PowerShell bulk-exfiltrates Documents folder via Invoke-WebRequest POST upload
This rule monitors for PowerShell commands that combine common data collection flags ('-Recurse', 'Documents') with 'Invoke-WebRequest' to perform a POST method upload. This pattern is commonly associated with the staging and exfiltration of sensitive files from local directories to a remote destination via HTTP/S.
Microsoft Sentinel (KQL)

