Vidar Stealer known sample hashes (v2.0-v3.4) in file/process events
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
Microsoft Sentinel (KQL)

This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.

Already have an account?