High Volume API Calls from Single IP

Detects an unusually high volume (100 or more within an hour) of API calls (POST, DELETE, PUT methods to URIs containing 'api') originating from a single IP address. This activity could indicate various malicious behaviors such as brute-force attacks, credential stuffing, web application attacks, or a denial-of-service attempt against the API endpoint.