Ransomware Restart Manager RmShutdown to release file locks
Detects the loading of rstrtmgr.dll by processes other than explorer.exe. Adversaries, particularly ransomware, utilize the Windows Restart Manager API (RmStartSession, RmRegisterResources, RmShutdown) to identify and forcibly terminate processes that hold file handles to files they intend to encrypt, thereby bypassing file-in-use locks.
YARA-L

