Bulk Data Staging via Large Archive Creation in Unusual Directories

Detects the creation of large archive files (.zip, .7z, .rar, .tar) exceeding 100MB within sensitive or high-risk directory paths such as Desktop, Temp, or AppData, or on non-system drives. This behavior is often associated with the staging of sensitive data for exfiltration.