Payroll Pirate: Bulk Graph API HR/Payroll Enumeration via Stolen OAuth Token

Detects high-volume, suspicious enumeration of HR and Payroll related information via Microsoft Graph API. The rule identifies anomalous behavior such as rapid bulk pagination, usage of suspicious user agents, and specific targeting of sensitive fields (e.g., department, job title) or keywords commonly associated with HR and financial data, likely indicating the use of a stolen OAuth token.