• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    JeetBot Twitch Extension C2 Communication and OAuth Token Exfiltration

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 24 days ago•0•0•2

    Detects network connections originating from browser processes to known JeetBot command and control (C2) infrastructure. The rule identifies suspicious C2 communication and, specifically, attempts at token exfiltration by monitoring for auth tokens in the URL of requests directed to known JeetBot hosts and Twitch-related infrastructure.

    Microsoft Sentinel (KQL)

    Tags

    T1071 - Application Layer ProtocolT1041 - Exfiltration Over C2 ChannelTA0010 - ExfiltrationNetwork Connection OutboundData ExfiltrationHTTP RequestWindowsWindows Defender Atpkql

    Found in

    • JeetBot Twitch Extension Steals OAuth TokensLast updated 24 days ago
    • JeetBot Twitch Extension Steals OAuth TokensLast updated 24 days ago
    • JeetBot Twitch Extension Steals OAuth TokensLast updated 24 days ago
    • JeetBot Twitch Extension Steals OAuth TokensLast updated 24 days ago
    • JeetBot Twitch Extension Steals OAuth TokensLast updated 24 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?