KRSID/UBP Asset Campaign IOC Hunt (Hashes, Domains, URL)
This rule monitors for known malicious file hashes (MD5) and network traffic (domains and specific URLs) associated with known threats. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential interactions with threat infrastructure.
Microsoft Sentinel (KQL)

