Best Detection of 2026 Series: Multi-Variant EDR-Killer Mass Process Termination
Detects a suspicious pattern of mass security process termination, where a process masquerading as legitimate consumer or gaming software (e.g., Kaspersky, Valorant, Javelin) repeatedly uses commands like taskkill, sc stop, or NtTerminateProcess to disable EDR agents and antivirus software within a short time window. This behavior is indicative of pre-ransomware staging activities used by threat actors.
YARA-L

