Grixba Security Product Enumeration and Defense Evasion from User-Writable Path

Detects reconnaissance and impairment attempts against security software (EDR, AV, backup) using WMI or taskkill/net commands. The rule specifically monitors for these actions when executed by processes originating from user-writable directories, a technique commonly associated with the Grixba infostealer dropped by Play Ransomware.