High Volume File Deletions Detected
This rule detects an unusually high volume of file deletion events on a device within a short time frame (100 or more files deleted within a 5-minute window). This activity can be indicative of malicious behaviors such as ransomware encrypting and deleting original files, data wiping attacks, or an adversary attempting to remove forensic evidence by deleting logs or other critical files.
Microsoft Sentinel (KQL)

