SMB Session Enumeration on Domain Controller

Detects high-frequency SMB (Logon Type 3) authentication events targeting Domain Controllers, specifically involving suspicious or generic accounts such as 'ANONYMOUS LOGON', 'Guest', empty usernames, or machine accounts. This behavior is indicative of network reconnaissance, session enumeration, or brute-force attempts targeting the domain.