BrowserCore.exe Driven via Stdin/Stdout Redirection (PRT Theft)
Detects suspicious execution of 'browsercore.exe' using common command-line interpreters (cmd.exe, powershell.exe, pwsh.exe). This pattern monitors for specific command-line arguments involving file redirection, content retrieval, or process spawning, which are often indicative of malicious activity or attempts to bypass security controls by leveraging legitimate-looking browser-related binaries.
Microsoft Sentinel (KQL)

