NightSpire Pre-Encryption Exfiltration Staging with Bulk File Modification

This rule detects potential data staging and exfiltration behavior characterized by large volumes of outbound network data combined with high frequency file write operations across multiple file types. It monitors Sysmon Event IDs 3 (Network connection) and 11 (FileCreate) to identify indicators often associated with pre-encryption staging by ransomware or data theft campaigns.