Ransomware Executable Targeting Cloud Storage
Detects the execution of known ransomware-related executables ('servertool.exe', 'encrypt.exe') when their command line arguments indicate interaction with cloud storage services such as OneDrive, SharePoint, GoogleDrive, Dropbox, or iCloud. This behavior is indicative of ransomware attempting to encrypt or exfiltrate data from cloud environments.
Microsoft Sentinel (KQL)

