Prinz Eugen Ransomware - File Compression Before Encryption
This rule detects a suspicious sequence of events indicative of ransomware activity, specifically the Prinz Eugen ransomware. It looks for the execution of common file compression utilities (7z.exe, rar.exe, WinRAR.exe, winzip.exe) followed by the execution of known ransomware encryption executables (servertool.exe, encrypt.exe) on the same device within a 30-minute window. This pattern suggests that an attacker is compressing files before encrypting them, a common tactic to reduce the size of data for faster encryption or exfiltration.
Microsoft Sentinel (KQL)

