ClawdBot Malware IOC Watchlist
This rule detects file and network indicators of compromise (IOCs) associated with the fake 'ClawdBot Agent' VS Code extension malware campaign. It looks for known malicious file hashes and network connections to C2 infrastructure, including specific C2 checks for ScreenConnect relay on port 8041.
Microsoft Sentinel (KQL)

