DXSCAN C2 malware detected via SHA-256 hash match
This rule monitors for the presence or execution of files matching a known set of SHA256 hashes associated with the 'DXSCAN' malware, utilizing both device file and process events.
Microsoft Sentinel (KQL)

