Chaos Ransomware Hash Detection
This rule detects the presence of known Chaos ransomware samples by matching their SHA256 hashes against process execution events and file events. If a process with a matching hash is executed or a file with a matching hash is observed, an alert will be triggered.
Microsoft Sentinel (KQL)

