Chrome/Edge CDP session bypasses CSP via Page.setBypassCSP over loopback debugging port
Detects instances of Chrome or Edge browsers initiating a network connection to the localhost (loopback) while executing commands associated with the Chrome DevTools Protocol, specifically targeting Page.setBypassCSP. This behavior is indicative of an adversary attempting to disable Content Security Policy (CSP) protections, often as part of a browser-based attack or malicious extension activity using remote debugging features.
Microsoft Sentinel (KQL)

