SessionGate Loader Masquerading as Security Tool with C2 within 60s

Detects the execution of known debugger/disassembler tools (Ghidra, dnSpy, x64dbg) that exhibit suspicious network behavior. The rule specifically looks for these tools initiating network connections to destinations outside of their official update or project domains shortly after execution, and filters out known good hash signatures.