Chrome/Edge launched headless with remote debugging and evasive flags
Detects the execution of Chrome or Microsoft Edge with remote debugging enabled (--remote-debugging-port) in a headless configuration (--headless=new). This combination is commonly used by automated scripts, scrapers, or potential malicious activity to interact with the browser remotely, which can be leveraged for data exfiltration, session hijacking, or automated attacks.
Microsoft Sentinel (KQL)

