Cloud Service Hijacking - Bulk VM Creation for Compute Abuse (T1496.004)

This rule detects potential cloud resource hijacking (e.g., cryptojacking) by monitoring for a sudden spike in the deployment of Azure virtual machines by a single user. It triggers if a user creates five or more virtual machines in a 10-minute window, specifically looking for deployments in regions where the user has not recently created VMs, or deployments utilizing high-compute SKUs commonly targeted for cryptocurrency mining.