High Volume Admin Share Activity

This rule detects a high volume of activity (10 or more events within an hour) to Windows administrative shares (C$, IPC$, ADMIN$) from a single source IP address. This behavior can indicate lateral movement, data exfiltration, or other malicious activity using legitimate administrative functions.