High SharePoint File Activity Across Multiple Sites

Detects users accessing, downloading, or copying a high volume of document files (>100 unique files) across multiple SharePoint sites (>1) within a single hour, excluding legitimate OneDrive sync client activity. The rule targets file types commonly associated with sensitive business data — Office documents, PDFs, archives, databases, email exports (PST/OST/MSG), and OneNote notebooks — and aggregates by user and hour to surface bulk collection patterns consistent with insider data theft, account compromise, or pre-exfiltration staging by ransomware affiliates