DeadLock Pre-Encryption Burst: Mass Security/Backup/RMM Process & Service Termination
This rule detects potential adversary activity aimed at disabling security tools, critical infrastructure services, or cloud synchronization agents. It monitors for a high volume (6 or more) of process termination commands (e.g., taskkill, net stop) or registry-based service disabling (Start value 4) targeting a predefined list of security and critical system services within a 3-minute window, which is indicative of an attempt to blind security monitoring or disrupt system availability.
Microsoft Sentinel (KQL)

