VS Code Extension Installation (Potential Token Theft via Jupyter Notebook)

Detects command-line installation of VS Code extensions. Malicious Jupyter notebooks can simulate keystrokes to silently install rogue extensions that steal GitHub tokens.

Microsoft Sentinel (KQL)