Cyclops Blink implant execution associated with credential harvesting on FMC
This rule monitors for process creation or file interaction events associated with a specific SHA256 file hash identified as malicious. It uses Microsoft Defender for Endpoint (MDE) logs to correlate both process execution and file activity related to this indicator of compromise.
Microsoft Sentinel (KQL)

