The ManualFinder and PDF Editor malware campaign represents a chain attack that turns legitimate-looking applications (well, I guess..) into information stealers and more. In this post, we'll walk through building a comprehensive KQL hunting query that leverages external IOC sources for real-time threat detection.
-----------------------------------------------------------------------------------------------------------------The Campaign OverviewOver the past week, Expel’s team dropped a blog po