FamousSparrow SparroWocky IOC hunt: hashes, C2 IPs, and domains
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
Microsoft Sentinel (KQL)

