msaRAT CDP-injected Base64ToArrayBuffer flow-controlled send queue (24KB threshold)
Detects malicious JavaScript injection attempts by msaRAT that leverage the Chrome DevTools Protocol (CDP) Runtime.evaluate method. The malware attempts to execute specific code snippets to facilitate flow-controlled data transfers over WebRTC DataChannels using Base64ToArrayBuffer conversions and a 24KB buffer threshold.
Microsoft Sentinel (KQL)

