CRPx0 Recon Commands Following Encoded PowerShell/Curl-Bash Execution
Detects host and user discovery commands (whoami, hostname, systeminfo, wmic) executed within a 15-minute window following a suspected CRPx0 ransomware execution event, identified by either encoded PowerShell or curl-to-bash activity.
YARA-L

