High Volume UDP Connections from a Single Process
This rule detects a high volume of UDP network connections originating from a single process on a device. A count exceeding 50 UDP connections from the same process to the same remote IP address is considered anomalous and could indicate a UDP flood or other denial-of-service attempt.
Microsoft Sentinel (KQL)

