Reflective DLL load within chrome.exe indicating V8/WASM sandbox escape
Detects the loading of reflective (memory-only) DLLs within the chrome.exe process address space. This activity is indicative of memory-based exploit chains, such as those that corrupt WebAssembly module metadata to facilitate arbitrary code execution following a sandbox escape.
Microsoft Sentinel (KQL)

