BlackHatSect0r GHOST-toolkit indicators across process/file/HTTP

This rule monitors process creation, file system activity, and HTTP logs for indicators associated with the 'GHOST-VAULT' or 'GHOST-CRED' threat activity. It specifically triggers on files or paths containing 'GHOST-VAULT-', processes named 'ghost_' or containing 'ghost_' in the command line, and HTTP requests containing 'GHOST-CRED/3.0', 'GHOST-VAULT/', or 'GHOST/0day'.