SMB IPC$ Share Enumeration on Domain Controllers (>20 in 5min)
Detects an abnormally high volume of connections to the hidden IPC$ administrative share on a Windows host within a short time window. This activity is often associated with lateral movement techniques, scanning, or brute-forcing attempts where adversaries interact with SMB shares for reconnaissance or remote execution.
Microsoft Sentinel (KQL)

