Bulk Azure AD Guest Account Invitations from Single User - T1136.003

Detects when a single user initiates a high volume (5 or more) of external guest user invitations within a one-hour window. This behavior can be indicative of reconnaissance or attempts to establish persistence by an compromised account by inviting external identities into the tenant.