BlueDelta HOOKEDGE/HEADLACE Hash Match or GUID Script Execution

This rule detects potentially malicious activity originating from Microsoft Word (WINWORD.EXE). It monitors for two specific patterns: the creation of script files (.bat, .vbs, .cmd) with GUID-based filenames in non-temp directories, and the creation or execution of files matching known malicious hashes associated with the Hookedge malware family.