Domain Password Policy Change Detection

This rule detects changes to the domain password policy by monitoring Windows Security Event ID 4739. It summarizes these events by the user who made the change and the time, providing an hourly count of policy modifications. This can help identify unauthorized or suspicious alterations to critical security policies.