Identity Compromise Followed by Ransomware-Like Endpoint Behavior

This rule detects potential ransomware activity by correlating risky user identity events (such as impossible travel or malicious IP access) with subsequent endpoint behavior typical of ransomware, specifically the deletion of shadow copies or system backups, or mass file modification activity occurring within a short window.