SparroWocky Call Stack Spoofing / Fake Return Address Indicator
This rule detects potential defense evasion activity identified by SentinelOne as call stack spoofing. The rule triggers when behavioral indicator tags related to spoofed call stacks, thread execution masking, or suspicious indicators involving RtlUserThreadStart, BaseThreadInitThunk, or kernel32.dll are detected, suggesting an attempt to hide malicious thread execution from security monitoring tools.
SentinelOne

