Suspicious Jupyter Notebook Execution

Detects the execution of Jupyter Notebooks from unexpected or temporary locations. Crafted Jupyter notebooks are the primary delivery mechanism for exploiting a zero-click/one-click GitHub token theft vulnerability in VS Code.

Microsoft Sentinel (KQL)