Privilege Escalation via Sensitive Privilege Use or Special Logon Rights Assignment
Detects accounts performing multiple sensitive operations, privilege assignments, or privileged service calls in a short timeframe, which may indicate account compromise, reconnaissance, or lateral movement.
Microsoft Sentinel (KQL)

