Remcos RAT Mutex Detection

This rule detects the creation or manipulation of mutexes by processes that contain keywords associated with the Remcos RAT (Remote Access Trojan). Specifically, it looks for command-line arguments containing "Remcos_Mutex_Inj", "Remcos_Mutex", "mutex", or "CreateMutex". This activity can indicate the presence or execution of Remcos RAT on a system, as mutexes are often used by malware for single-instance enforcement or inter-process communication.