High Frequency File Rename Activity
Detects a high volume of file rename events initiated by a single process on a device within a short time window (5 minutes). This behavior is often indicative of ransomware activity, where files are renamed as part of the encryption or extortion process.
Microsoft Sentinel (KQL)

