Rapuncel Browser App-Bound Encryption Bypass via Elevation Service
This rule detects indicators of the Rapuncel browser injection by monitoring for the creation of a known malicious DLL hash on disk, identifying non-standard parent processes invoking elevation_service.exe, and detecting the loading of unrecognized DLLs into Google Chrome or Microsoft Edge browser processes.
Cortex XDR

