DragonForce Locker taskkill of DB/Backup/AV processes pre-encryption
This rule detects the use of 'taskkill.exe' to terminate critical services, including security software (MsMpEng.exe), database processes (sql.exe, oracle.exe, sqlservr.exe), and common user applications (outlook.exe, onedrive.exe). This behavior is characteristic of the DragonForce ransomware, which disables protective services and applications before encryption to minimize interference and ensure successful file locking.
Sigma

