T1486 Ransomware: Mass Extension Rename & Ransom Note Drop
This rule detects ransomware activity by identifying two primary indicators: a high volume of file renames to common ransomware extensions within a 5-minute window, and the creation of known ransom notes across multiple directories. It excludes processes signed by trusted vendors to minimize noise.
SentinelOne

