High Volume SharePoint Sharing Activity
This rule detects an unusually high volume of SharePoint sharing invitation creations or sharing setting modifications by a single user within an hour. This could indicate an attacker attempting to exfiltrate data or broadly share sensitive information.
Microsoft Sentinel (KQL)

