Detection of Known Malicious Hashes (Nuso)

This rule detects the presence of files on endpoints that match a list of known malicious SHA256 hashes associated with the Nuso malware. It queries DeviceFileEvents to identify any file with a matching hash.