High Volume Registry Access to HKLM or System Registry

This rule detects an unusually high volume of registry access events (Event ID 4656) targeting either the 'HKLM' (HKEY_LOCAL_MACHINE) hive or 'System Registry' within a one-hour window. A count of 10 or more such events by a single user on a specific computer within an hour is considered suspicious. This activity could indicate an adversary attempting to enumerate system configurations, modify system settings for persistence, or gather information.