High Volume SMB/RPC Connections from a Single Account

This rule detects an unusually high volume of successful network connections over SMB (ports 135, 139, 445) originating from a single account within a one-hour window. This behavior can be indicative of lateral movement, reconnaissance, or data exfiltration activities using SMB/RPC.