Browser-rendered phishing login page via local blob: URL
Detects browser navigation events where the target URL is a locally generated 'blob:' URI that includes keywords associated with common credential harvesting targets (e.g., login, Microsoft 365, DocuSign). Adversaries use blob URIs to render phishing content directly from memory, which can help bypass certain static URL reputation filters and email security gateways.
Microsoft Sentinel (KQL)

