Chaos Ransomware Hash Detection

This rule detects the presence of known Chaos ransomware samples by matching their SHA256 hashes against process execution events and file events. If a process with a matching hash is executed or a file with a matching hash is observed, an alert will be triggered.