POC, crowdsec detects via sysmon files created with ransomware extension then kills the PID
Primary LanguageGoMIT LicenseMIT