Suspicious Node/Bun Traffic to GitHub API
Detects Node.js or Bun processes making network connections to the GitHub API. This rule is designed to identify potential exfiltration attempts, specifically referencing the Miasma campaign which spoofs a 'python-requests/2.31.0' User-Agent to evade network detection while exfiltrating credentials to api.github.com/repos/.
Microsoft Sentinel (KQL)

