Cyclops Blink implant execution associated with credential harvesting on FMC

This rule monitors for process creation or file interaction events associated with a specific SHA256 file hash identified as malicious. It uses Microsoft Defender for Endpoint (MDE) logs to correlate both process execution and file activity related to this indicator of compromise.