Best Detection of 2026 Series: Pre-Exfiltration Data Staging in Archive Files
Detects a sequence of activity indicative of data exfiltration preparation. This rule identifies the creation of multiple large archive files (.zip, .rar, .7z) in temporary or staging directories on an endpoint, followed by a network connection transferring a significant volume of data to an external, non-private IP address within a 30-minute window.
CQL

