Phantom Stealer Indicators
This rule detects the execution of processes with command lines containing indicators associated with 'Phantom Stealer' malware, such as 'phantom stealer', 'stealer.dll', 'phantom.exe', or 'phtantom'. This could indicate an attempt to load or execute the stealer.
Microsoft Sentinel (KQL)

