BloodHound/SharpHound AD Recon via LDAP Bursts & Process Creation
Detects the execution of BloodHound related processes combined with a high volume of LDAP queries (Event ID 1644), which is indicative of Active Directory environment reconnaissance.
Microsoft Sentinel (KQL)

