Detect Ransomware File Encryption Activity

This rule detects potential ransomware activity by monitoring for a high volume of file creation or renaming events where the new file names end with common ransomware extensions such as '.encrypted', '.locked', or '.crypted'. It aggregates these events over 5-minute intervals and triggers if 50 or more such files are observed on a single device.