Unusual Service Account Activity
This rule detects unusual logon activity for service accounts. It identifies service accounts by looking for a dollar sign ($) at the end of the username. The rule then counts logons, unique IP addresses, and unique computers for these service accounts within one-hour bins. An alert is triggered if a service account has 10 or more logons or logs in from 5 or more unique IP addresses within that hour, indicating potential abuse or compromise.
Microsoft Sentinel (KQL)

