Grixba Ransomware Custom Mutex Detection
This rule detects the creation of a specific mutex pattern associated with the Grixba ransomware. The mutex name starts with 'CPFATE_' and contains the .NET framework version string 'v4.0.30319', which is a unique artifact used by Grixba to ensure only one instance of itself is running.
Microsoft Sentinel (KQL)

