Sauron Ransomware cmd.exe Execution with systemki.exe or sysklnd.exe File Discovery
Detects the execution of cmd.exe triggered by specific potentially malicious filenames or involving known ransomware-related artifacts, such as 'boottel.dat', ransomware note files, or specific suspicious file extensions like '.SZO'. This is indicative of ransomware deployment or post-compromise cleanup and extortion activities.
Microsoft Sentinel (KQL)

