High Volume IPC$ Admin Share Access
This rule detects a high volume of access attempts to the IPC$ administrative share from a single source IP address within a one-hour window. This behavior can be indicative of reconnaissance, lateral movement, or other malicious activities using SMB/Windows Admin Shares.
Microsoft Sentinel (KQL)

