Repeated Azure Public Access or Firewall Configuration Changes

This rule detects repeated successful operations related to public access or firewall configuration changes within Azure Activity Logs. A high count (3 or more) of such operations by the same caller within an hour could indicate malicious activity, such as an attacker attempting to open up network access to compromised resources or exfiltrate data.