AD User Password Change Attempt - Unauthorized Self-Service or Forced Reset
Detects instances where an interactive user initiates a password change attempt as captured by Windows Security Event ID 4723. The rule filters out non-interactive accounts (ending with '$') and common service account naming patterns to focus on human-driven account modifications.
Microsoft Sentinel (KQL)

