Headless Edge launched with remote debugging and off-screen window (TWINLOOT)

Detects Microsoft Edge being launched in a headless state with remote debugging enabled, hidden window dimensions, and a specific temporary user data directory naming convention. This pattern is characteristic of the TWINLOOT technique, where an adversary controls a headless browser via the Chrome DevTools Protocol (CDP) to conduct C2 communications and data exfiltration through legitimate Microsoft Graph API endpoints, effectively blending malicious traffic with normal browser activity.