High Volume Access to Admin Shares
This rule detects a high volume of access attempts (5 or more within an hour) to administrative shares (C$, D$, E$, ADMIN$) from a single source IP address. This activity can be indicative of lateral movement, data exfiltration, or reconnaissance by an adversary attempting to gain access to sensitive information or spread malware across the network.
Microsoft Sentinel (KQL)

