Payroll Pirate - Graph API HR Payroll Account Enumeration

Detects the use of PowerShell to perform automated reconnaissance against Microsoft Graph API endpoints, specifically targeting HR, payroll, and personal user data. This activity is associated with post-compromise behaviors seen in campaigns like Payroll Pirate, where attackers utilize compromised credentials to harvest sensitive organizational information.