/root
/var/log/messages
More
SPLUNK PILL 101-#AA02-Process change
SPLUNK PILL 101-#AA01-External device
SPLUNK PILL 101-#AA00-Possible ransomware
Entropy: A Key Component in Malware Analysis
user id