Domain Group Changes by User
This rule detects and summarizes changes to domain groups (creation, deletion, or modification) by a specific user. It counts the number of such changes per user per hour, which can be indicative of administrative activity or potential malicious account manipulation.
Microsoft Sentinel (KQL)

