Detection of Gh0st RAT Related File Hashes in Process or File Events

This rule detects the presence of files or processes with known malicious SHA256 or MD5 hashes. It queries both DeviceProcessEvents and DeviceFileEvents to identify if any file or running process matches the provided list of malicious hashes.