High Volume of File Renames by a Single Account

This rule detects an unusually high number of file rename events (20 or more within a 1-hour window) initiated by a single process account. This behavior can be indicative of malicious activities such as data staging prior to exfiltration, ransomware encryption, or attempts to evade detection by renaming malicious files or legitimate system utilities.