AtomSilo Long-Dwell Ransomware - Process Dormant 7+ Days then Sudden Mass File Activity
This rule identifies potentially malicious activity where a process, which has been dormant on the system for at least 7 days since its initial start, suddenly performs a high volume (more than 50 events in 60 seconds) of file creation or modification events. This behavior pattern is often indicative of ransomware encryption activities, where malware lies dormant before initiating a rapid, destructive encryption cycle.
Splunk (SPL)

