Qilin/BARADAI Ransomware Bulk File Rename with Unknown Extension (T1486)

This rule detects high-frequency file renaming or creation activities within a short timeframe (60 seconds) that involve uncommon file extensions. This behavior is highly characteristic of the encryption phase of ransomware attacks, where malicious processes quickly rename or encrypt files across the system.