INC Ransomware Discovery Command Chain Within 60 Seconds
Detects the execution of five specific Windows reconnaissance utilities (net.exe, nltest.exe, whoami.exe, ipconfig.exe, and systeminfo.exe) by the same parent process within a 60-second window. This behavior pattern is highly characteristic of an automated discovery phase during a post-exploitation engagement, where an actor attempts to quickly gather system and network environment information.
Splunk (SPL)

