Multiple Service Crashes on Domain Controller
This rule detects when critical Windows services or processes associated with Active Directory (NTDS, Netlogon, LSASS, LDAP) or the Print Spooler (Spooler, spoolsv.exe) crash multiple times (3 or more) on a machine within a 7-day period. This could indicate instability, a denial-of-service attempt, or a system compromise affecting core services.
Microsoft Sentinel (KQL)

