DEF CON 34 – Hausknecht/Maxwell-Stewart – Copilot Studio / low-code sandbox escape — anomalous native process from Power Platform runtime

This rule detects potentially unauthorized command-line activity originating from Power Platform-related execution environments (such as Copilot Studio or Power Platform sandboxes). It specifically monitors for the execution of common system administration binaries like cmd, powershell, or curl, which, when triggered from within a low-code/cloud runtime environment, may indicate a sandbox escape or an attempt to interact with the underlying host operating system.