• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    DragonForce Ransomware Pre-Encryption Process Kill: MsMpEng/SQL/Oracle

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•5

    Detects when a single process terminates two or more critical security, database, or backup related processes within a short window. This behavior is often associated with adversary attempts to disable security controls or disrupt database operations, commonly observed during the impact phase of an attack or preparatory to data destruction/encryption.

    Cortex XDR

    Tags

    T1489 - Service StopT1685 - Disable or Modify ToolsTA0040 - ImpactProcess TerminationProcess TamperingAntivirus DetectionWindowsWindows Eventlog SystemWindows Defender AvMssql ServerOracle Db

    Found in

    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?