Repeated Access Attempts to Credential Stores
This rule detects repeated access attempts (3 or more within an hour) to critical credential storage processes or files, specifically lsass.exe, the Security Account Manager (SAM) database, or the NTDS.dit file. Such activity is indicative of credential theft attempts by an adversary.
Microsoft Sentinel (KQL)

