Best Detection of 2026 Series: High-Volume LDAP Enumeration Burst Indicative of BloodHound-Style AD Recon

Detects a single host or account generating a high volume of LDAP queries (typical of reconnaissance tools like BloodHound/SharpHound) within a 10-minute time window. The rule specifically looks for more than 500 LDAP queries targeted at a limited number of Domain Controllers.