SophosLabs has published the IOC for Kaseya ransomware. Below is the query that fetches the IOC published on GitHub and check for matching Indicators present in the endpoint.
/* EDR Query to check for matching REvil-Kaseya-IOC's */
--VARIABLE $$StartTime...