GhostCode Phishing Kit - Web Request & Session Artifact Hunt
Detects network activity and HTTP request headers associated with the GhostCode phishing kit. The rule identifies specific URI patterns, custom site keys, malicious User-Agent strings, and session cookie artifacts indicative of interaction with a phishing server.
Microsoft Sentinel (KQL)

