Post-Exfil Anti-Forensic Database Wipe Following Bulk Outbound Transfer
Detects high-risk destructive database operations (DROP, TRUNCATE, or UPDATE) on sensitive tables executed within six hours of a large outbound data transfer from the same host, a pattern indicative of anti-forensic database wiping following data exfiltration.
Microsoft Sentinel (KQL)

