If there is a public tool, which checks for Pegasus, NSO will simply modify Pegasus to evade such a trivial detection. I would even assume that every Pegasus-infection is pretty unique due to mutations between every sample.
Everybody who claims Pegasus and other ATP-malware is trivial to detect has no clue what he's talking about.