Headless Edge launched with remote debugging and off-screen window (TWINLOOT)
Detects Microsoft Edge being launched in a headless state with remote debugging enabled, hidden window dimensions, and a specific temporary user data directory naming convention. This pattern is characteristic of the TWINLOOT technique, where an adversary controls a headless browser via the Chrome DevTools Protocol (CDP) to conduct C2 communications and data exfiltration through legitimate Microsoft Graph API endpoints, effectively blending malicious traffic with normal browser activity.
Microsoft Sentinel (KQL)

