DragonForce ransomware mass termination of security/backup/office processes

Detects the rapid termination of multiple critical processes (security, database, backup, and office applications) consistent with the kill list behavior exhibited by DragonForce ransomware. The rule monitors for a pattern of three or more unique processes from a defined list being terminated on the same host within a 5-minute window, a common precursor to file encryption.