Ransomware Behavioral Indicators Detected
This rule detects potential ransomware activity by identifying a combination of three distinct behaviors occurring on a single endpoint within a short window: high-volume file modifications (indicative of file encryption), deletion of system recovery resources (e.g., volume shadow copies, backup catalogs), and high-frequency network activity (indicative of data exfiltration). The rule uses cross-event correlation to reduce false positives by requiring all three signals to be present.
SentinelOne

