Shai-Hulud KQL from Unit 42 Threat Hunting

This rule set detects several indicators of compromise related to the Shai-Hulud threat activity. It identifies specific malicious file hashes (SHA256) for 'bundle.js' files, the execution of the 'trufflehog' tool which is often abused for secrets discovery, the presence of a malicious YAML file named 'shai-hulud-workflow.yml', and network connections to 'webhook.site' domains, optionally with a specific URI, which are used for data exfiltration or command and control.