Suspicious Jupyter Notebook Execution
Detects the execution of Jupyter Notebooks from unexpected or temporary locations. Crafted Jupyter notebooks are the primary delivery mechanism for exploiting a zero-click/one-click GitHub token theft vulnerability in VS Code.
Microsoft Sentinel (KQL)

