Suspicious Command Line Keywords
This rule detects suspicious command-line activity by looking for the presence of keywords such as 'risk', 'threat', or 'exposure' in process creation command lines (Event ID 4688). It then aggregates these events by computer and account over one-hour intervals and flags if 3 or more such activities occur within that hour, indicating potential reconnaissance or malicious activity.
Microsoft Sentinel (KQL)

