Ransomware Series: Gentlemen Ransomware Hidden Share Staging with Anonymous/Ever

Detects the creation of hidden administrative shares (ending in $) mapped to local directories (e.g., C:\Temp) with unrestricted 'Everyone' or 'ANONYMOUS LOGON' permissions. This technique is used by the Gentlemen ransomware to stage malicious binaries for lateral movement and subsequent encryption across the network. The rule monitors for 'net share' commands with specific permission grants, 'icacls' operations modifying access for anonymous users, and registry changes to 'NullSessionShares' configurations.