Excessive LDAP Connections to DC Ports from Single Source IP
This rule detects high-volume connection requests to LDAP services (default ports 389, 636, 3268, 3269). A high number of connections from a single source to a destination within a short time window may indicate automated reconnaissance, LDAP enumeration, or brute-force attempts against domain services.
Microsoft Sentinel (KQL)

