High Volume of File or Registry Permission Changes
This rule detects an unusually high volume (10 or more within an hour) of permission changes to files or registry keys by a single user. This activity can be indicative of an adversary attempting to modify access controls to facilitate persistence, privilege escalation, or defense evasion.
Microsoft Sentinel (KQL)

