Service worker registration on cdn.bloom[.]io phishing page
Detects the registration of browser service workers from suspicious sources. Service workers can be used to maintain persistence, intercept network requests, or perform browser-based man-in-the-middle attacks. This rule specifically alerts on service workers initialized with 'blob:' URIs or those originating from the suspicious 'cdn.bloom.io' domain.
Microsoft Sentinel (KQL)

