Ransomware Mass File Encryption/Renaming via Known Extensions (T1486)

Detects high volumes of file operations (creation, rename, or modification) where files are given extensions typically associated with ransomware (e.g., .locked, .encrypted). The rule aggregates activity by process and endpoint and triggers an alert when the number of such operations exceeds a defined threshold, while excluding known legitimate backup and security software.