Native ELF/.node binary executed from VS Code extensions folder
Detects the execution of native binaries, the creation/modification of Node-API (.node) files, or the loading of .node modules from Visual Studio Code extensions directories. This behavior is indicative of malicious VS Code extensions attempting to execute arbitrary native code for reconnaissance, persistence, or exfiltration.
Microsoft Sentinel (KQL)

