T1486 Ransomware Mass Extension Rename or Ransom Note Drop via SMB

Detects anomalous SMB traffic indicating potential ransomware activity. The rule monitors for file operations associated with known ransomware naming conventions (e.g., README.txt, DECRYPT_INSTRUCTIONS) or common ransomware-related extensions. It uses a threshold to identify high-frequency occurrences within a short timeframe, suggesting bulk file renaming or ransom note creation typical of encryption phases.