High Volume Object Access Attempts
This rule detects a high volume of failed object access attempts (EventID 4674) by a single user on a specific computer within a one-hour window. This could indicate an adversary attempting to discover or access sensitive resources, potentially as part of privilege escalation or data exfiltration efforts.
Microsoft Sentinel (KQL)

