Ruby gem payload disables TLS verification via OpenSSL::SSL::VERIFY_NONE
Detects Ruby processes executing with arguments explicitly disabling SSL/TLS verification (OpenSSL::SSL::VERIFY_NONE) while correlating with the presence of suspicious helper scripts ('loader.rb' or 'script.rb') within Ruby gem-related directories. This behavior is indicative of an adversary attempting to perform man-in-the-middle attacks or bypass security controls for outbound C2 communications.
Microsoft Sentinel (KQL)

