Grixba Play Ransomware Network Recon via net.exe, WMIC Remote Node, and GT_NET.exe Drop
Detects Grixba infostealer activity associated with the Play Ransomware group. The rule monitors for network host and share enumeration using net.exe and WMIC, and tracks the execution of the Grixba binary GT_NET.exe from the non-standard path C:\Users\Public\Music\.
Sigma

