VOID#GEIST KQL
This rule detects various stages of the VOID#GEIST multi-stage Python loader as described in the Securonix blog. It identifies initial batch file execution, Chrome decoy PDF lures, hidden PowerShell relaunching of the batch file, persistence via the Startup folder, curl commands downloading zip payloads, Python embedded runtime downloads, and final Python payload execution. The rule is designed to catch the distinct command-line patterns associated with each stage of this specific malware.
Microsoft Sentinel (KQL)

