Pre-Ransomware Data Staging via Large Archive Creation in Temp/UNC Paths
Detects the creation of multiple archive files (ZIP, 7Z, RAR, TAR) by common utilities (7z, WinRAR, tar) in sensitive temporary directories (Temp, tmp). The rule aggregates activity over a 10-minute window to identify suspicious staging behaviors often associated with ransomware data preparation.
Splunk (SPL)

