Mustang Panda OIC PlugX campaign IOC sweep: hashes, C2 IP, domains
This rule monitors endpoint telemetry for indicators of compromise (IOCs) associated with known malicious activity. It checks for file creation, process execution, and network connections that match a defined list of malicious file hashes (SHA256, SHA1, MD5), C2 IP addresses, and malicious domains or URL patterns.
Microsoft Sentinel (KQL)

