Codefinger Ransomware - AWS S3 SSE-C PutObject with Customer-Provided Encryption Key

Detects high-frequency S3 PutObject requests that utilize Customer-Provided Encryption Keys (SSE-C). A high count of such operations within a short window can be indicative of ransomware activity, where an adversary encrypts data within the victim's cloud storage using their own keys to prevent access by the owner.