VectraRAT: Known sample hashes across file and process events
Detects the presence of known file hashes associated with Vectra Remote Access Trojan (RAT). The rule monitors both file creation/existence events and process execution events where the SHA256 hash matches the identified indicators of compromise.
Microsoft Sentinel (KQL)

