Ransomware Mass File Rename to Known Encrypted Extensions
This rule detects a high frequency of file rename or modification events targeting files with extensions commonly associated with ransomware. It filters out activity from processes signed by trusted vendors like Microsoft, Symantec, Sophos, and Trend Micro to reduce noise, flagging mass rename operations that could indicate an active ransomware encryption process.
SentinelOne

