SnakeBiteAgent webcam/mic surveillance via unsigned process + capture DLLs
Detects suspicious processes executing from user-writable directories (Temp, AppData, Downloads) that are either unsigned or command-line focused on media capture (camera/microphone), while also loading media-related DLLs. The rule correlates this activity with potential spawned hidden UI processes (explorer/notepad) and AnyDesk remote access connectivity, which is a behavioral pattern indicative of remote monitoring or data exfiltration malware.
Microsoft Sentinel (KQL)

