UC-L3-001
Rapid File Encryption Detection
Windows File Auditing / Sysmon Event ID 11
Use case development / Protect Against Ransomware / Detect Ransomware Encryption Activity
sigma
Detection rule
title: Rapid File Modification Indicating Ransomware
status: experimental
description: Detects rapid modification of many files which may indicate ransomware encryption activity
logsource:
product: windows
category: file_event
detection:
selection:
EventType: 'FileModified'
timeframe: 1m
condition: selection | count(TargetFilename) by ComputerName > 100
falsepositives:
- Legitimate bulk file operations
- Backup software
level: high
tags:
- attack.impact
- attack.t1486Test cases
- Trigger by encrypting 100+ files in under a minute
- Verify no alert during normal backup operations
False positive guidance
Tune threshold based on environment. Whitelist backup software and known bulk operations.