SleeperGem CI/CD Environment Variable Enumeration for Sandbox Evasion
Detects processes attempting to enumerate common CI/CD environment variables, a technique observed in the SleeperGem supply chain attack used for sandbox evasion and environment awareness to determine if the malware is running in a CI/CD build environment.
Microsoft Sentinel (KQL)

