Detect Suspicious File Extension Changes (Ransomware)

This rule detects suspicious file renaming activities indicative of ransomware. It specifically looks for files that previously had common document extensions (.doc, .xls, .ppt) being renamed to extensions commonly associated with encryption by ransomware (.encrypted, .locked, .crypted, .ecc). The rule triggers if 20 or more such renames occur within a 5-minute window on a single device.