Detection of Known Malicious Hashes (Nuso)
This rule detects the presence of files on endpoints that match a list of known malicious SHA256 hashes associated with the Nuso malware. It queries DeviceFileEvents to identify any file with a matching hash.
Microsoft Sentinel (KQL)

