Ransomware Series: Mass Security Tool and Service Termination Preceding Encryption

Detects a suspicious burst of commands commonly used to disable security services, antivirus, or backup agents on a single host. The rule monitors for a high frequency of taskkill, net stop, sc stop, or PowerShell Stop-Service operations targeting a predefined list of sensitive security software process and service names within a short timeframe, which is a common precursor to ransomware encryption.