The Gentlemen RaaS Go Ransomware: Mass File Access + Outbound C2

This rule detects a process identified as a Go-compiled binary (via command-line arguments like 'goroutine' or 'runtime.main') that exhibits rapid, high-volume file interactions (more than 100 files accessed or created in a 60-second window) alongside outbound network connectivity. This behavior is indicative of malicious automated activity such as file encryption for ransomware or rapid data staging and exfiltration.