Direct Markdown Image/Link Exfil Payload (attacker.com / evil.com) - ATR-2026-01454 (78838bff-060b-5085-823d-19e336a265c9)
Detects markdown image and link syntax that directly embeds attacker-controlled domains (attacker.com, evil.com, exfil., collect.) with exfiltration-specific query parameters. Unlike ATR-2026-00501 (which detects instruction patterns) and ATR-2026-01453 (which detects the base64-QUERY template), this rule detects the artifact itself when it appears directly in input — e.g. a raw payload like "" or "Click here". These appear as standalone injection payloads or embedded in social-engineering text.