High Volume Remote Desktop Session Changes
This rule detects a high volume of remote desktop session changes (logon/logoff) for a single user within a one-hour window. Event IDs 4778 and 4779 indicate a session reconnected or disconnected, respectively. A high count (>=10) could suggest suspicious activity such as session hijacking, rapid reconnections by an attacker, or automated tools interacting with remote sessions.
Microsoft Sentinel (KQL)

