Anti-sandbox process count gate before GRAYRABBIT loader XOR key decryption
Detects execution of the GRAYRABBIT loader (specifically 7z.exe from the Users\Public\Documents staging path) in environments exhibiting low process count activity (<= 50 processes). This behavior is consistent with anti-sandbox checks used by this loader to gate XOR key derivation for payload decryption.
Microsoft Sentinel (KQL)

