RANSOMWARE - Qilin Rust Payload Leak-Site Exfil Upload
Detects outbound HTTP PUT requests characteristic of data exfiltration associated with Qilin ransomware. The rule monitors for the use of command-line tools like s5cmd or rclone for uploading data, often used during the double extortion phase where stolen data is uploaded to leak sites.
Suricata

