KongTuke - Nexthink extension

This rule detects the presence and activity of known malicious browser extensions, specifically 'NexShield' and those associated with the 'KongTuke' campaign. It identifies these extensions by their unique IDs found in file paths or names, network connections to associated malicious IPs or domains, and specific file hashes. The rule correlates file events, network events, and process events to provide a comprehensive view of the malicious extension's activity, including when it was first and last seen, the browsers involved, and the files/folders it interacted with.