Tox Ransomware C2 Channel Establishment with Host Encryption Activity
Detects potential execution of a Tox ransomware negotiation channel by monitoring for processes that exhibit a high rate of file writes (potential encryption activity) in conjunction with command-line arguments containing specific patterns such as a 76-character string or the 'tox://' URI scheme, which are associated with Tox ransomware client activity.
Splunk (SPL)

