DEF CON 34 – Sternberg/Poran/Bobrov – Remote agent takeover via observability/edge SaaS misuse (Cloudflare/Sentry pivot)

This rule detects high volumes of network traffic originating from processes other than common web browsers (chrome, msedge, firefox) to specific edge computing and logging infrastructure (ingest.sentry.io, workers.dev, pages.dev). This behavior is indicative of non-browser processes, potentially malicious implants or scripts, using legitimate cloud-based edge services as command-and-control (C2) infrastructure or for data exfiltration.