Prinz Eugen Ransomware Network Share Access Before Encryption

This rule detects a pattern of network shared folder access followed by the execution of known ransomware executables ('servertool.exe', 'encrypt.exe') within a 45-minute window. This behavior is indicative of ransomware preparing to encrypt data on network shares.