The Gentlemen Ransomware - Large HTTPS Exfiltration Without Preceding File Encryption Activity

Detects high volume HTTPS outbound traffic (greater than 50MB within a 5-minute window) from a host that does not show evidence of preceding file encryption or volume shadow copy deletion activity. This rule is designed to identify potential unauthorized data exfiltration that deviates from typical ransomware-associated behavior patterns.