Payload Ransomware File Renamed
Detects when a file is renamed to have the suffix ':payload' and the initiating process's file name is the same as the previous file name. This behavior can be indicative of Payload Ransomware to hide or modify files.
Microsoft Sentinel (KQL)

