High Volume of Patch/Update Activity

This rule detects a high volume of process creation events (EventID 4688) where the command line contains keywords indicative of patching or updating activity (e.g., 'patch', 'update', 'KB', 'hotfix'). Specifically, it triggers if 3 or more such events occur on a single computer within an hour. This could indicate legitimate system updates, but also potentially malicious activity masquerading as updates to evade detection or perform unauthorized actions.