Repeated SeDebugPrivilege or SeImpersonatePrivilege Usage
This rule detects when a user account repeatedly (3 or more times within an hour) requests either 'SeDebugPrivilege' or 'SeImpersonatePrivilege' (Event ID 4672). This behavior can be indicative of an attacker attempting to escalate privileges or manipulate access tokens, often seen in techniques like token impersonation or debugging processes for malicious purposes.
Microsoft Sentinel (KQL)

