Suspicious Account Delegation Changes

This rule detects suspicious changes to account delegation settings by monitoring Security Event ID 5136 for modifications to the 'msDS-AllowedToDelegateTo' attribute. It specifically looks for instances where an account's delegation settings are changed two or more times within an hour, which could indicate an adversary attempting to establish persistence or elevate privileges through constrained delegation.