ShadowAgent Malware Hash Detection

This rule detects the presence of known ShadowAgent malware files on devices by matching their SHA256 hashes. It queries 'DeviceFileEvents' to identify any files with SHA256 hashes that are part of a predefined list associated with ShadowAgent.