Nightspire Ransomware Multi-Stage Activity Detectio
This rule correlates multiple low-to-medium confidence signals across file, process, network, and registry events to detect potential ransomware activity. The rule identifies suspicious behaviors including mass file renames, creation of known ransom note file types in multiple directories, shadow copy deletion via system utilities, disabling of antivirus and security monitoring, large archive staging, unauthorized outbound network connections, and suspicious process injection. Alerts are generated based on the aggregation and frequency of these signals, indicating a high probability of ransomware-related malicious activity.
Microsoft Sentinel (KQL)

