CQL Hubby ByteRay
← All queries

Charon Ransomware Detection and Correlation

The query chain detects and correlates multiple indicators of the Charon ransomware attack lifecycle, including ransomware package writes, malicious DLL sideloading, process execution triggers (notably via svchost.exe), creation of ransom notes, and suspicious service creation (WWC.sys). It merges these findings across several event types to confirm successful ransomware deployment.

CQL · Falcon Next-Gen SIEMCopy query
Loading query…
Charon_Ransomware_Detection_and_Correlation.yml
Aamir Muhammad
Hunting
Endpoint
Insight

Want this running in your SIEM — with someone on call?

Our Managed SIEM team operates CrowdStrike Falcon Next-Gen SIEM in production, with over 350 battle-tested use cases and 24/7 incident response behind them.

Talk to the SIEM team