Prinz Eugen Ransomware Password Derivation Function Detection
This rule detects the use of password derivation functions (like argon2id, scrypt, pbkdf2) in command lines, which can be indicative of ransomware activity, specifically associated with Prinz Eugen. It focuses on processes like 'servertool.exe', 'encrypt.exe', and 'powershell.exe' initiating these commands.
Microsoft Sentinel (KQL)

