Kali365 / EvilTokens - Linux Chrome Leaking Server OS
Detects Railway server OS leaking via User-Agent during automated token exchanges. This rule specifically looks for sign-in logs where the User-Agent string indicates a Linux x86_64 system and a Chrome browser version 145 or 146.
Microsoft Sentinel (KQL)

