Rhysida Pre-Encryption: meow_*.dll Creation with Suspicious Child Process
This rule detects a suspicious pattern involving two events occurring on the same host: the creation of a DLL file with a 'meow_' prefix (potentially associated with known malware patterns) and the execution of a command-line interpreter (cmd.exe, powershell.exe, or pwsh.exe) as a child process of suspicious parent processes like svchost.exe, services.exe, dllhost.exe, or msiexec.exe.
Splunk (SPL)

