Here is a query that looks at process and cmdlines to map to IOCs in the Exfiltration tactic for Mitre
-- VARIABLE $$Start Search on Date and Time$$ DATE
-- VARIABLE $$Total Hours to search$$ STRING
-- Process cmdline IOC search, mapped to MITRE...