BlueDelta HOOKEDGE/HEADLACE Hash Match & GUID Script Naming
Detects execution or file presence associated with HOOKEDGE/HEADLACE malware. This rule uses a dual-approach: matching known malicious file hashes (SHA256) and monitoring for specific script files (bat, vbs, cmd) following a GUID-formatted naming convention typically used by the HOOKEDGE installer chain.
Splunk (SPL)

