Mass Upload to S3 via s5cmd or AWS CLI (Exfiltration)

Detects the use of command-line tools like s5cmd or aws-cli to synchronize or copy data to an Amazon S3 bucket. The rule identifies suspicious patterns by looking for specific transfer commands combined with recursive or high-concurrency flags that indicate mass data movement often associated with exfiltration.