SparroWocky Call Stack Spoofing via RtlUserThreadStart Masquerade
Detects instances of thread execution where the start module is identified as a critical system component (ntdll.dll or kernel32.dll) but the associated call trace contains 'UNKNOWN' entries. This behavior is indicative of call stack spoofing, a technique used by malicious software to hide the true origin of code execution and evade endpoint security analysis by mimicking legitimate thread start addresses.
Sigma

