Injected Code — Host / Hardware Inventory Exfiltration - ATR-2026-01893 (7b54916d-ee60-525e-87c5-8fc6b12e41d4)
Detects injected code that enumerates the host (installed packages, virtual memory, USB devices, disk partitions, network interfaces, sound devices) and ships the inventory to a remote server via HTTP POST or MQTT. Host fingerprinting is reconnaissance preceding targeted compromise.