Suspicious Rapid File Modification and Canary File Interaction

This rule detects potential ransomware activity by monitoring for two key signals: interaction with known canary/trap files designed to detect unauthorized access, and rapid, mass file modification of common user data extensions within a short timeframe. Either behavior is indicative of encryption or automated file destruction processes typical of ransomware attacks.