Settra-style _win64.exe ransomware execution from unusual folders
Detects the execution of files ending in '_win64.exe' from 'Perflogs' or 'Documents' directories, which is a known behavior of the Settra ransomware. The rule filters out common system and program file paths to reduce noise.
Sigma

