Cloud Account Enumeration Anomaly

Detects anomalous, high-frequency account enumeration activity in cloud audit logs, specifically targeting user, group, device, and service principal listing operations. This behavior is indicative of potential reconnaissance or discovery efforts by an attacker who has compromised a user account.