Ransomware Series: WinRAR Archive Staging for Double-Extortion Data Exfiltration

Detects the execution of WinRAR utilities (WinRAR.exe, Rar.exe) with suspicious command-line arguments typically associated with data staging, archiving, or encryption. The rule filters out legitimate WinRAR installations and only triggers when the process is spawned by a script interpreter (e.g., PowerShell, CMD) or operates within sensitive file paths (e.g., Users, Shares, Finance, HR, Backup).