Detect execution of backup_dfs.py associated with the FortiBleed campaign

This rule detects suspicious activity related to high-volume Server Message Block (SMB) share enumeration and the execution of a specific Python script named 'backup_dfs.py'. It combines three detection logics: identifying processes executing 'backup_dfs.py', detecting an unusual number of SMB network connections to common administrative shares (SYSVOL, NETLOGON, DFS), and flagging high-volume SMB-related identity directory events targeting SYSVOL or NETLOGON. This behavior could indicate an adversary performing discovery of network shares, collecting data, or preparing for data exfiltration.