Bulk Scanning of Client-Side JS Files and Admin/Console Endpoints
Detects automated reconnaissance and enumeration of sensitive web application paths (admin, config, environment files, etc.) from a single source IP. The rule identifies high-frequency request patterns that target specific non-public surface areas while excluding known search engine crawlers and monitoring bots.
Microsoft Sentinel (KQL)

