Prinz Eugen Ransomware Network Share Access Before Encryption
This rule detects a pattern of network shared folder access followed by the execution of known ransomware executables ('servertool.exe', 'encrypt.exe') within a 45-minute window. This behavior is indicative of ransomware preparing to encrypt data on network shares.
Microsoft Sentinel (KQL)

