GhostCode Phishing Kit - Known File Hash Match
This rule detects the presence of files matching known SHA256 hashes associated with the GhostCode phishing kit. It monitors for these files both in email attachments and on local device filesystems to identify potential delivery and execution of malicious phishing payloads.
Microsoft Sentinel (KQL)

