Containerized Bun Execution from Ephemeral Storage
Detects Bun processes launched from temporary locations within containers. This behavior may indicate unauthorized package execution, workload drift, malicious tooling deployment, or post-compromise activity in cloud-native environments.
Microsoft Sentinel (KQL)

