Repeated Security Patch Activity
This rule detects an unusual number of process creations (Event ID 4688) containing both 'security' and 'patch' in their command line within a one-hour window on a single computer. This could indicate automated patching activity, but a high volume might also suggest suspicious system modifications or an attempt to disguise malicious activity as legitimate patching.
Microsoft Sentinel (KQL)

