Multiple RDP Logons by Privileged Accounts
This rule detects multiple successful RDP logons (LogonType 10) within a one-hour window by accounts containing '$' (often machine accounts) or 'admin' (privileged accounts). This behavior can be indicative of an adversary attempting to gain remote access and potentially deploy ransomware or other malicious payloads, especially if multiple source IPs are observed.
Microsoft Sentinel (KQL)

