BabylonRAT-style unauthorized write to Windows HOSTS file
This rule detects modifications to the Windows hosts file by unauthorized processes. The hosts file is often targeted by adversaries to redirect network traffic, intercept communications, or prevent access to security-related websites.
SentinelOne

