Suspicious Process Writing to Multiple File Types
This rule detects a single process creating a large number of files with diverse file types within a short time frame (5 minutes). This behavior can be indicative of malicious activity such as ransomware encrypting files, data staging for exfiltration, or malware dropping multiple components.
Microsoft Sentinel (KQL)

