PathWiper Destructive Wiper - Anti-Recovery, Bulk File Overwrite, and Network Beacon
This rule correlates multiple suspicious activities indicative of ransomware or destructive attacks. It detects a combination of volume shadow copy deletion, bulk file modifications, creation of suspicious scheduled tasks, and network connections occurring during periods of high file write activity. The rule triggers when multiple signals are observed or when specific high-fidelity destructive indicators are present.
Microsoft Sentinel (KQL)

