Ransomware Series: Gentlemen Ransomware Mass Process/Service Termination Pre-Enc

Detects the mass termination of security, backup, database, and virtualization services and processes. The rule monitors for the use of 'taskkill', 'sc', and 'net stop' commands, targeting a list of processes and services often associated with pre-encryption cleanup activities by ransomware actors to neutralize security tools and data access controls.