GTG-20006 Midnight Blizzard-style Known Malicious File/Hash Hunt
This rule monitors for the execution or presence of specific file names and SHA256 hashes known to be associated with malicious activity. It queries both process creation and file events to identify these indicators of compromise (IOCs).
Microsoft Sentinel (KQL)

