Containerized Bun Execution from Ephemeral Storage

Detects Bun processes launched from temporary locations within containers. This behavior may indicate unauthorized package execution, workload drift, malicious tooling deployment, or post-compromise activity in cloud-native environments.

Microsoft Sentinel (KQL)