Unusual Number of Patch/Update/Fix File Creations/Modifications
This rule detects an unusual number of file creations or modifications where the filename contains keywords like 'patch', 'update', or 'fix' by a single account within a one-hour window. This could indicate an automated patching process, software deployment, or potentially malicious activity attempting to modify system files under the guise of an update.
Microsoft Sentinel (KQL)

