Edgecution: Edge Browser Extension Sandbox Escape Spawning Python Backdoor
This rule detects potentially malicious behavior associated with web browser processes, including the execution of Python scripts, the loading of browser extensions from non-standard directories like AppData or Temp, the creation of Python scripts by browsers in temp folders, and outbound network connections by Python processes following browser activity. These patterns are often associated with browser-based exploitation, extension-based malware, or initial access stages where a browser is used as a conduit for malicious code execution.
Microsoft Sentinel (KQL)

