JADEPUFFER Agentic Ransomware IOC Hunt
Detects indicators associated with the exploitation of CVE-2025-3248 in Langflow. The rule identifies anomalous web requests targeting the /api/v1/validate/code endpoint, subsequent suspicious process creation (base64 encoded payloads in Python/shell), and network communication with identified command and control (C2) or data exfiltration IP addresses. It also includes alerts for observed contact with known extortion email addresses.
Microsoft Sentinel (KQL)

