Rapid File Activity in Local Temp Directory

Detects high-frequency file creation, opening, or modification events within the Windows AppData Local Temp directory. This behavior, often involving specific obfuscated file names or known malicious process names, is a common indicator of malware payload staging or execution patterns, such as those observed in AsyncRAT infections.