Rapid Lateral Movement Pattern Detected

This rule detects a high frequency of successful network connections from a single device to multiple unique destination IP addresses within a one-hour window. The targeted ports (445, 139, 3389, 22, 21) are commonly used for remote administrative access, file transfers, and remote shell services, which are frequently leveraged by adversaries for lateral movement. The threshold of 3 unique targets in an hour may indicate automated scanning or credential brute-forcing activity across the network.