Ransomware Mass File Encryption: High-Volume Rename/Modify with Encrypted Extensions
This rule identifies potential ransomware activity by detecting a process performing a high volume of file rename or modification operations within a short time window. It specifically targets files with known ransomware extensions or those using randomized 6-8 character alphanumeric extensions, while excluding common administrative, backup, and temporary file operations performed by trusted software.
SentinelOne

