Unauthorized Access Attempts to Sensitive AD Objects
This rule detects multiple unauthorized access attempts (5 or more within an hour) to sensitive Active Directory objects such as 'Admin', 'krbtgt', or 'Domain Admins'. It leverages Windows Security Event ID 4662, which indicates an operation was performed on an object, and filters for specific sensitive object names. The rule then groups these attempts by object, IP address, and user, alerting when a threshold of attempts is met.
Microsoft Sentinel (KQL)

