Ransomware-like File Activity Detection
This rule detects suspicious file activity indicative of ransomware by monitoring for a high volume of file creations or renames where the filenames contain common ransomware-related extensions such as '.encrypted', '.locked', or '.ransom'. It aggregates these events over a one-hour period per device and triggers if 20 or more such events occur.
Microsoft Sentinel (KQL)

