VS Code (Code.exe) spawns suspicious child process post folder-open
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
Microsoft Sentinel (KQL)

