Sality-style modification of Windows HOSTS file

This rule detects modifications, creation, or renaming of the Windows hosts file located at 'C:\Windows\System32\drivers\etc\hosts'. Adversaries often modify this file to redirect network traffic, facilitate phishing, or prevent security tools from communicating with update or telemetry servers.