Dark Caracal GoCaracal: AppData hex-folder drops or known C2 IPs
This rule monitors for two distinct indicators of compromise: it detects the execution of files dropped into specific patterns within the 'AppData\Roaming' directory (associated with potential GoCaracal malware) and identifies network connections to known C2 infrastructure associated with GoCaracal and Bandook malware families.
Microsoft Sentinel (KQL)

