AI-Powered Ransomware 3.0 - Rapid Encryption with Simultaneous Exfiltration

This rule correlates rapid file modifications (potential encryption or mass deletion) with the execution of commands known to inhibit system recovery (e.g., deleting shadow copies or modifying boot recovery settings) and significant outbound network data transfers from the same host. This pattern is characteristic of ransomware deployment.