Headless Edge Browser Launched with CDP Remote Debugging, Off-Screen Window, and Launcher Temp Profile
Detects msedge.exe launched headless (--headless / --headless=new) with CDP remote debugging enabled (--remote-debugging-port=), a temp profile directory matching the launcher-edge- naming pattern, and window flags positioning it off-screen (--window-position=-32000,-32000, --window-size=1,1). This combination matches the TWINLOOT implant's technique of spawning a headless Edge instance with a Chrome DevTools Protocol connection, using the browser's authenticated same-origin session to proxy Microsoft Graph API C2 traffic so it blends in with legitimate browser network activity while remaining invisible on-screen. Excludes known browser-automation/CI framework parent processes and the --enable-automation flag to reduce false positives. references: - https://detections.ai/inspirations/01a01ade-da64-7718-8281-426118171583 - https://detections.ai/inspirations/01a01ade-d9a6-742d-8e2f-f60b5efce416 - https://detections.ai/inspirations/01a01ade-da04-700d-ba14-769eef28e475 - https://github.com/ontinue-research/threat-intel-iocs/blob/main/Public/2026-07-27-TWINLOOT-IOCs.md - https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/
Sigma

