- Added rule_response_action to Ransomware Activity alerts, returning a terminate_sessions field that reflects automatic session termination based on admin settings.
- Behavior controlled by the Terminate Target User Sessions rule (off by default); other Shield alerts still return null for this parameter.
- Documentation updated to describe the new field and its usage.