GoCaracal extended build keylogger via SetWindowsHookEx keyboard hook
Detects the execution of known GoCaracal malware samples, identified by specific file hashes or staging file paths, occurring in conjunction with low-level keyboard hook installations using SetWindowsHookEx. This behavior is indicative of active keylogging activity.
Microsoft Sentinel (KQL)

