Potential Information Disclosure Attempt via IIS Logs

This rule detects potential information disclosure attempts by monitoring W3C IIS logs for repeated queries containing keywords like 'version', 'build', or 'debug'. A high frequency (5 or more attempts within an hour) from a single IP address suggests an adversary is trying to enumerate software versions or debug information, which can be used for further reconnaissance or exploit development.