Renamed Gpg.EXE Execution — Detection Rule

Detects the execution of a renamed "gpg.exe". Often used by ransomware and loaders to decrypt/encrypt data.

Read the full analysis on IntelFusions