ClawHub Backdoor Skill Multi-Layer Encoded Payload Decoding Chain in Python
Detects Python processes executing complex, multi-layered decoding chains (Base64, ROT13, and Hex) in their command line arguments. This pattern is often used by malicious AI skill backdoors, such as ClawHub, to obfuscate payload execution and evade signature-based detection.
Microsoft Sentinel (KQL)

