High Volume of HTTP Errors from Single IP
This rule detects a high volume (50 or more) of HTTP errors (status codes 400 and above) originating from a single client IP address within a 5-minute time window. This behavior can be indicative of various malicious activities such as brute-force attacks, web application vulnerability scanning, or denial-of-service attempts against a web server.
Microsoft Sentinel (KQL)

