Hardware watchdog device manipulation to force reboot

This rule detects unauthorized access or modifications to hardware watchdog device files (/dev/watchdog, /dev/watchdog0, /dev/misc/watchdog, /dev/FTWDT101_watchdog) on Linux systems. Adversaries may manipulate these files to disable the hardware watchdog's automatic reboot functionality, potentially to maintain persistence or to ensure system stability while performing malicious actions without the risk of an unexpected forced reboot.